An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cimg | Cimg | .220 (including) | .220 (including) |
| Cimg | Ubuntu | artful | * |
| Cimg | Ubuntu | bionic | * |
| Cimg | Ubuntu | cosmic | * |
| Cimg | Ubuntu | esm-apps/bionic | * |
| Cimg | Ubuntu | esm-apps/xenial | * |
| Cimg | Ubuntu | trusty | * |
| Cimg | Ubuntu | upstream | * |
| Cimg | Ubuntu | xenial | * |