Medium severity5.5NVD Advisory· Published May 10, 2017· Updated May 13, 2026
CVE-2017-8891
CVE-2017-8891
Description
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- openwall.com/lists/oss-security/2017/05/10/1nvdMailing ListPatchThird Party Advisory
- github.com/dropbox/lepton/commit/82167c144a322cc956da45407f6dce8d4303d346nvdIssue TrackingPatchThird Party Advisory
- github.com/dropbox/lepton/issues/87nvdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.