libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvips | Libvips | 8.12.0 (including) | 8.14.4 (excluding) |
Vips | Ubuntu | bionic | * |
Vips | Ubuntu | esm-apps/jammy | * |
Vips | Ubuntu | esm-apps/noble | * |
Vips | Ubuntu | jammy | * |
Vips | Ubuntu | lunar | * |
Vips | Ubuntu | mantic | * |
Vips | Ubuntu | noble | * |
Vips | Ubuntu | trusty | * |
Vips | Ubuntu | upstream | * |
Vips | Ubuntu | xenial | * |