VYPR
Medium severity5.5OSV Advisory· Published Aug 31, 2022· Updated Jun 17, 2026

CVE-2022-1325

CVE-2022-1325

Description

A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual buffer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • GreycLab/CimgOSV2 versions
    v.2.3.0, v.2.3.1, v.2.3.2, …+ 1 more
    • (no CPE)range: v.2.3.0, v.2.3.1, v.2.3.2, …
    • (no CPE)
  • cpe:2.3:a:cimg:cimg:*:*:*:*:*:*:*:*
    Range: <3.1.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.