CVE-2023-40032
published 2023-09-11CVE-2023-40032: libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vips | < vips 8.14.1-3+deb12u1 (bookworm) | vips 8.14.1-3+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| libvips | libvips | < 8.14.4 | 8.14.4 |
| libvips | libvips | >= 8.12.0 < 8.14.4 | 8.14.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
VIPS vulnerabilities
vendor_ubuntu·2023-10-18·CVSS 7.5
CVE-2020-20739 [HIGH] VIPS vulnerabilities
Title: VIPS vulnerabilities
Summary: Several security issues were fixed in VIPS.
Ziqiang Gu discovered that VIPS could be made to dereference a NULL
pointer. If a user or automated system were tricked into processing
a specially crafted input image file, an attacker could possibly use
this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-7998)
It was discovered that VIPS did not properly handle uninitialized memory
locations when processing corrupted input image data. An attacker could
possibly use this issue to generate output images that expose sensitive
information. This issue only affected Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2019-6976)
It was discovered that VIPS did not properly manage memory due to an
uninitiali
Debian
CVE-2023-40032: vips - libvips is a demand-driven, horizontally threaded image processing library. A sp...
vendor_debian·2023·CVSS 5.5
CVE-2023-40032 [MEDIUM] CVE-2023-40032: vips - libvips is a demand-driven, horizontally threaded image processing library. A sp...
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
Scope: local
bookworm: resolved (fixed in 8.14.1-3+deb12u1)
bullseye: resolved
forky: resolved (fixed in 8.14.4-1)
sid: resolved (fixed in 8.14.4-1)
trixie: resolved (fixed in 8.14.4-1)
OSV
vips vulnerabilities
osv·2023-10-18·CVSS 7.5
CVE-2018-7998 [HIGH] vips vulnerabilities
vips vulnerabilities
Ziqiang Gu discovered that VIPS could be made to dereference a NULL
pointer. If a user or automated system were tricked into processing
a specially crafted input image file, an attacker could possibly use
this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-7998)
It was discovered that VIPS did not properly handle uninitialized memory
locations when processing corrupted input image data. An attacker could
possibly use this issue to generate output images that expose sensitive
information. This issue only affected Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2019-6976)
It was discovered that VIPS did not properly manage memory due to an
uninitialized variable. If a user or automated system were tricked into
OSV
CVE-2023-40032: libvips is a demand-driven, horizontally threaded image processing library
osv·2023-09-11·CVSS 5.5
CVE-2023-40032 [MEDIUM] CVE-2023-40032: libvips is a demand-driven, horizontally threaded image processing library
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/libvips/libvips/commit/e091d65835966ef56d53a4105a7362cafdb1582bhttps://github.com/libvips/libvips/pull/3604https://github.com/libvips/libvips/security/advisories/GHSA-33qp-9pq7-9584https://lists.fedoraproject.org/archives/list/[email protected]/message/YU2FFC47X2XDEGEHEWAGLU5L3R6FEYD2/https://github.com/libvips/libvips/commit/e091d65835966ef56d53a4105a7362cafdb1582bhttps://github.com/libvips/libvips/pull/3604https://github.com/libvips/libvips/security/advisories/GHSA-33qp-9pq7-9584https://lists.fedoraproject.org/archives/list/[email protected]/message/YU2FFC47X2XDEGEHEWAGLU5L3R6FEYD2/
2023-09-11
Published