It was discovered that allocation failures could occur in CImg when loading crafted bmp images. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-7587)
It was discovered that a heap-based buffer over-read existed in CImg when loading crafted bmp images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-7588)
It was discovered that a double free existed in CImg when loading crafted bmp images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-7589)
{ "binaries": [ { "binary_name": "cimg-dev", "binary_version": "1.7.9+dfsg-2ubuntu0.18.04.1" }, { "binary_name": "cimg-doc", "binary_version": "1.7.9+dfsg-2ubuntu0.18.04.1" }, { "binary_name": "cimg-examples", "binary_version": "1.7.9+dfsg-2ubuntu0.18.04.1" } ], "availability": "No subscription required" }