Vulnerability Description
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enlightenment | Imlib2 | 1.6.0 |
Related Weaknesses (CWE)
References
- https://git.enlightenment.org/legacy/imlib2.git/commit/?id=c95f938ff1effaf91729cPatchThird Party Advisory
- https://git.enlightenment.org/legacy/imlib2.git/commit/?id=c95f938ff1effaf91729cPatchThird Party Advisory
FAQ
What is CVE-2020-12761?
CVE-2020-12761 is a vulnerability with a CVSS score of 9.1 (CRITICAL). modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
How severe is CVE-2020-12761?
CVE-2020-12761 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-12761?
Check the references section above for vendor advisories and patch information. Affected products include: Enlightenment Imlib2.