6.4
CVSSv2

CVE-2020-12761

Published: 09/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

enlightenment imlib2 1.6.0

Vendor Advisories

Debian Bug report logs - #960192 imlib2: CVE-2020-12761 Package: src:imlib2; Maintainer for src:imlib2 is Markus Koschany <apo@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 May 2020 13:39:04 UTC Severity: important Tags: security, upstream Found in version imlib2/161-1 Reply ...