VYPR
Medium severity5.3NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026

CVE-2024-48854

CVE-2024-48854

Description

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

Affected products

5
  • cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:blackberry:qnx_software_development_platform:8.0:*:*:*:*:*:*:*
    • (no CPE)range: 8.0, 7.1 and 7.0
  • QNX/SDPllm-fuzzy
    Range: 8.0, 7.1, 7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.