
Cloud Vulnerability DB
A community-led vulnerabilities database
Deark v.1.6.2 contains a stack overflow vulnerability in the doprismread_palette() function located in /modules/atari-img.c. The vulnerability was discovered and reported on September 18, 2022 (GitHub Issue).
The vulnerability is a stack-buffer-overflow that occurs in the doprismread_palette function at line 331 of modules/atari-img.c. When processing certain malformed input files, the function attempts to read 4 bytes beyond the bounds of an allocated buffer named 'pal1' on the stack. This was confirmed through AddressSanitizer analysis which showed the overflow occurring at offset 1056 of a buffer allocated with size [32, 1056) (GitHub Issue).
The vulnerability could lead to a denial of service condition through application crash. Given that it's a stack buffer overflow, there may also be potential for arbitrary code execution, though this has not been explicitly confirmed (GitHub Issue).
Users should upgrade to a version newer than v1.6.2. The vulnerability was reported to the project maintainers through GitHub's issue tracking system (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."