Medium severity5.5OSV Advisory· Published Aug 31, 2022· Updated Jun 17, 2026
CVE-2022-1325
CVE-2022-1325
Description
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual buffer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/GreycLab/CImg/commit/619cb58dd90b4e03ac68286c70ed98acbefd1c90nvdPatchThird Party Advisory
- github.com/GreycLab/CImg/pull/348nvdPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingPatchThird Party Advisory
- github.com/GreycLab/CImg/issues/343nvdExploitIssue TrackingThird Party Advisory
- huntr.dev/bounties/a5e4fc45-8f14-4dd1-811b-740fc50c95d2/nvdExploitThird Party Advisory
- access.redhat.com/security/cve/CVE-2022-1325nvdBroken Link
News mentions
0No linked articles in our index yet.