VendorsPotrace Projectpotrace1.14
Vulnerabilities

Potrace Project Potrace 1.14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-7263
The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.
Published 2017-03-26 · Modified
7.8EPSS 0.016
CVE-2017-12067
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
Published 2017-08-01 · Modified
7.5EPSS 0.011