
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image (NVD, CVE). The vulnerability was discovered in early 2024 and affects the image handling functionality of the Imlib2 library.
The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The issue is classified as CWE-787 (Out-of-bounds Write) and CWE-122 (Heap-based Buffer Overflow) (NVD). The vulnerability was introduced in version 1.6.0 and fixed in version 1.10.0 (Debian).
The heap buffer overflow vulnerability could potentially lead to high impacts on confidentiality, integrity, and availability of affected systems. Given the CVSS score and vector string, successful exploitation could allow attackers to execute arbitrary code or cause system crashes when processing crafted images (NVD).
The vulnerability has been fixed in imlib2 version 1.10.0. Various Linux distributions have released security updates: Debian Bullseye (1.7.1-2+deb11u1), Bookworm (1.10.0-4+deb12u1), and Sid/Trixie (1.12.3-2) (Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."