CVE-2016-5637
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted BPG image, related to a "type confusion" issue.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| libbpg_project | libbpg | {"startIncluding":"0.9.5","endIncluding":"0.9.7"} | |
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.