CVE Vulnerabilities

CVE-2024-48854

Off-by-one Error

Published: Jan 14, 2025 | Modified: Jan 21, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
Qnx_software_development_platformBlackberry7.0 (including)7.0 (including)
Qnx_software_development_platformBlackberry7.1 (including)7.1 (including)
Qnx_software_development_platformBlackberry8.0 (including)8.0 (including)

Potential Mitigations

References