It was discovered that allocation failures could occur in CImg when loading crafted bmp images. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-7587)
It was discovered that a heap-based buffer over-read existed in CImg when loading crafted bmp images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-7588)
It was discovered that a double free existed in CImg when loading crafted bmp images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-7589)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.7.9+dfsg-2ubuntu0.18.04.1", "binary_name": "cimg-dev" }, { "binary_version": "1.7.9+dfsg-2ubuntu0.18.04.1", "binary_name": "cimg-doc" }, { "binary_version": "1.7.9+dfsg-2ubuntu0.18.04.1", "binary_name": "cimg-examples" } ] }