CVE-2020-25693

HIGH

CImg < 2.9.3 - Integer Overflow and Heap Buffer Overflow in load_pnm()

Title source: llm
STIX 2.1

Description

A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to application availability or data integrity.

References (4)

Core 4
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1893377

Scores

CVSS v3 8.1
EPSS 0.0147
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-190 CWE-787
Status published
Products (4)
cimg/cimg < 2.9.3
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
Published Dec 03, 2020
Tracked Since Feb 18, 2026