CVE Vulnerabilities

CVE-2023-40032

NULL Pointer Dereference

Published: Sep 11, 2023 | Modified: Apr 21, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FedoraFedoraproject39 (including)39 (including)
VipsUbuntubionic*
VipsUbuntuesm-apps/jammy*
VipsUbuntuesm-apps/noble*
VipsUbuntujammy*
VipsUbuntulunar*
VipsUbuntumantic*
VipsUbuntunoble*
VipsUbuntutrusty*
VipsUbuntuupstream*
VipsUbuntuxenial*

Potential Mitigations

References