4.3
CVSSv2

CVE-2016-8685

Published: 31/01/2017 Updated: 05/02/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The findnext function in decompose.c in potrace 1.13 allows remote malicious users to cause a denial of service (invalid memory access and crash) via a crafted BMP image.

Vulnerable Product Search on Vulmon Subscribe to Product

potrace project potrace

Vendor Advisories

Debian Bug report logs - #843861 potrace: CVE-2016-8685: invalid memory access in findnext Package: potrace; Maintainer for potrace is Bartosz Fenski <fenio@debianorg>; Source for potrace is src:potrace (PTS, buildd, popcon) Reported by: Chris Lamb <lamby@debianorg> Date: Thu, 10 Nov 2016 10:21:02 UTC Severity: se ...
Debian Bug report logs - #850595 potrace: CVE-2016-8686: memory allocation failure Package: potrace; Maintainer for potrace is Bartosz Fenski <fenio@debianorg>; Source for potrace is src:potrace (PTS, buildd, popcon) Reported by: Chris Lamb <lamby@debianorg> Date: Thu, 10 Nov 2016 10:21:02 UTC Severity: normal Tag ...