Impact
A flaw in libvips’ old‑style Radiance RLE decoder allows the decoder to read one byte beyond the beginning of a scanline when the line starts with a repeat marker. The code accesses a heap location that holds four bytes of adjacent memory, which may contain image data or unrelated data. The read can leak these four bytes to the application, resulting in a modest disclosure of sensitive information stored on the heap at the time of decoding.
Affected Systems
The vulnerability exists in all libvips releases older than 8.18.3. Software that uses the foreign Radiance loader to import RLE‐encoded Radiance images is potentially exposed. The issue was fixed in libvips 8.18.3 and later releases.
Risk and Exploitability
The CVSS base score of 4.8 indicates a medium impact with limited severity. The EPSS score is less than 1 %, and the vulnerability is not listed in CISA’s KEV catalog, implying no confirmed exploitation. The likely attack vector is a local or remote application that processes a crafted Radiance file; by supplying such a file an attacker could obtain a few unintended bytes from memory. Overall, the risk is moderate, but the absence of active exploitation makes it a lower‑to‑moderate priority.
OpenCVE Enrichment