Impact
A flaw in libvips 8.19.0 allows manipulation of the alpha_band argument in the vips_unpremultiply_build function to cause an out‑of‑bounds read. The vulnerability is limited to local execution and could expose arbitrary memory contents to the attacker, creating a potential information disclosure. The weakness is a classic out‑of‑bounds read (CWE‑125) that can be triggered by crafted input to the conversion routine.
Affected Systems
The issue is found in libvips version 8.19.0, the distribution currently in use. No other versions are reported as affected, and earlier releases are not known to contain this specific bug.
Risk and Exploitability
The CVSS score of 4.8 places the vulnerability in a low‑to‑medium severity range. The EPSS score indicates a exploitation probability of less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires local execution and the attack surface is limited to processes with access to the vulnerable library, the overall risk to remote adversaries is low, but internal users or compromised local processes can leverage the flaw for data leakage.
OpenCVE Enrichment