Description


im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.

Related CPE's


Vulnerable


o

fedoraproject

fedora

2

Weaknesses



CWE-909

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2020-11-20T18:15:11.710Z

5 years ago

Last modified

2024-11-21T04:12:15.553Z

1 year ago