OSV-2023-709

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kimageformats/OSV-2023-709.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-709
Published
2023-08-18T14:02:53.146275Z
Modified
2023-08-20T14:15:45.069773Z
Summary
Heap-buffer-overflow in QOIHandler::read
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=61528

Crash type: Heap-buffer-overflow READ 1
Crash state:
QOIHandler::read
kimgio_fuzzer.cc
References

Affected packages

OSS-Fuzz / kimageformats

Package

Name
kimageformats
Purl
pkg:generic/kimageformats

Affected ranges

Type
GIT
Repo
https://invent.kde.org/frameworks/kimageformats.git
Events
Introduced
dd4576a4729cc9c44d0a7f10cad02331402afd45
Fixed
274f30e00840cfe0d4476f3b7959cf847a4f9104
Introduced
4c3ade04dd1ded3999426e6e913b9bbd46aca7c0
Fixed
6254529d2d427a5558deb15efb61929dab93e3f4

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "94385407351c08698e10cecc227b49878b9540a3:4348a0973382b68de4dc1fa146596d67467d1518",
    "fixed_range": "4348a0973382b68de4dc1fa146596d67467d1518:274f30e00840cfe0d4476f3b7959cf847a4f9104"
}