CVE-2024-25447
published 2024-02-09CVE-2024-25447: An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.69%
48.7th percentile
An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imlib2 | < imlib2 1.10.0-2 (bookworm) | imlib2 1.10.0-2 (bookworm) |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.7.1-2+deb11u1 | 1.7.1-2+deb11u1 |
| enlightenment | imlib2 | >= 0 < 1.10.0-2 | 1.10.0-2 |
| enlightenment | imlib2 | >= 0 < 1.10.0-2 | 1.10.0-2 |
| enlightenment | imlib2 | >= 0 < 1.10.0-2 | 1.10.0-2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-25447: An issue in the imlib_load_image_with_error_return function of imlib2 v1
osv·2024-02-09·CVSS 8.8
CVE-2024-25447 [HIGH] CVE-2024-25447: An issue in the imlib_load_image_with_error_return function of imlib2 v1
An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
GHSA
GHSA-m7x8-rvvc-g243: An issue in the imlib_load_image_with_error_return function of imlib2 v1
ghsa_unreviewed·2024-02-09
CVE-2024-25447 [HIGH] CWE-787 GHSA-m7x8-rvvc-g243: An issue in the imlib_load_image_with_error_return function of imlib2 v1
An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Debian
CVE-2024-25447: imlib2 - An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 all...
vendor_debian·2024·CVSS 8.8
CVE-2024-25447 [HIGH] CVE-2024-25447: imlib2 - An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 all...
An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
Scope: local
bookworm: resolved (fixed in 1.10.0-2)
bullseye: resolved (fixed in 1.7.1-2+deb11u1)
forky: resolved (fixed in 1.10.0-2)
sid: resolved (fixed in 1.10.0-2)
trixie: resolved (fixed in 1.10.0-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-09
Published