An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cimg | Cimg | .220 (including) | .220 (including) |
Cimg | Ubuntu | artful | * |
Cimg | Ubuntu | bionic | * |
Cimg | Ubuntu | cosmic | * |
Cimg | Ubuntu | esm-apps/xenial | * |
Cimg | Ubuntu | trusty | * |
Cimg | Ubuntu | upstream | * |
Cimg | Ubuntu | xenial | * |