CVE-2017-18215
05.03.2018, 18:29
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xv_project | xv | 3.10a:a |
| opensuse | leap | 42.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References