Description
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44643 | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input. |
Ubuntu USN |
USN-6437-1 | VIPS vulnerabilities |
References
History
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora |
|
| CPEs | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | |
| Vendors & Products |
Fedoraproject
Fedoraproject fedora |
Thu, 13 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input. | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input. |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:03:21.242Z
Reserved: 2023-08-08T13:46:25.244Z
Link: CVE-2023-40032
No data.
Status : Analyzed
Published: 2023-09-11T19:15:43.603
Modified: 2025-04-21T13:45:44.587
Link: CVE-2023-40032
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN