Vulnerabilities > CVE-2016-8695 - NULL Pointer Dereference vulnerability in Potrace Project Potrace
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8696.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DLA-675.NASL |
description | Multiple vulnerabilities have been found in potrace. CVE-2013-7437 Multiple integer overflows in potrace 1.11 allow remote attackers to cause a denial of service (crash) via large dimensions in a BMP image, which triggers a buffer overflow. This bug was reported by Murray McAllister of the Red Hat Security Response Team. CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 Multiple NULL pointer dereferences in bm_readbody_bmp. This bug was discovered by Agostino Sarubbo of Gentoo. CVE-2016-8697 Division by zero in bm_new. This bug was discovered by Agostino Sarubbo of Gentoo. CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 Multiple heap-based buffer overflows in bm_readbody_bmp. This bug was discovered by Agostino Sarubbo of Gentoo. For Debian 7 |
last seen | 2020-03-17 |
modified | 2016-10-27 |
plugin id | 94293 |
published | 2016-10-27 |
reporter | This script is Copyright (C) 2016-2020 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/94293 |
title | Debian DLA-675-1 : potrace security update |
code |
|
References
- http://potrace.sourceforge.net/ChangeLog
- http://potrace.sourceforge.net/ChangeLog
- http://www.openwall.com/lists/oss-security/2016/08/18/11
- http://www.openwall.com/lists/oss-security/2016/08/18/11
- http://www.openwall.com/lists/oss-security/2016/10/16/12
- http://www.openwall.com/lists/oss-security/2016/10/16/12
- http://www.securityfocus.com/bid/93778
- http://www.securityfocus.com/bid/93778
- https://blogs.gentoo.org/ago/2016/08/08/potrace-multiple-three-null-pointer-dereference-in-bm_readbody_bmp-bitmap_io-c/
- https://blogs.gentoo.org/ago/2016/08/08/potrace-multiple-three-null-pointer-dereference-in-bm_readbody_bmp-bitmap_io-c/