A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as 24795bb3d19d84f7b6f5ed86451ad556c8f2fe70. It is advisable to implement a patch to correct this issue.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 4.0 | 1.9 | Low | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P |
| 3.1 | 3 | Low | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C |
| 3.0 | 3 | Low | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C |
| 2.0 | 1.3 | Low | CVSS:2.0/AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C |
| Product | Vendor | Version |
|---|---|---|
| libvips | n/a | < 10.0.14393.7159 |
| libvips | n/a | < * |