libvips 是一个内存占用低且处理速度快的图像处理库。在版本 8.18.3 之前,如果 libvips 在构建时未启用 libtiff 支持但启用了 ImageMagick 支持,通过 VipsForeignLoadMagick 加载经过精心构造的多页 TIFF 文件时,可能会导致组合帧高度发生整数溢出。libvips/foreign/magick6load.c 和 libvips/foreign/magick7load.c 中的易受攻击代码在未进行边界检查的情况下,将每页的高度(Ysize)与帧数(n_fra
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69242 | 8.4 HIGH | libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-con |
| CVE-2026-70654 | 5.8 MEDIUM | libvips: A well-crafted PPM image processed via a custom source could lead to possible hea |
| CVE-2026-70653 | 4.8 MEDIUM | libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radianc |
| CVE-2026-70652 | 2.0 LOW | libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG wit |
No comments yet