Leptonica 1.71

CPE Details

Leptonica 1.71
1.71
2019-08-08 15:15 +00:00
2019-08-08 15:15 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:leptonica:leptonica:1.71:*:*:*:*:*:*:*

Informations

Vendor

leptonica

Product

leptonica

Version

1.71

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-38266 2022-09-08 22:00 +00:00 An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
6.5
MEDIUM
CVE-2020-36281 2021-03-11 23:00 +00:00 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
7.5
HIGH
CVE-2020-36280 2021-03-11 23:00 +00:00 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
7.5
HIGH
CVE-2020-36279 2021-03-11 23:00 +00:00 Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
7.5
HIGH
CVE-2020-36278 2021-03-11 22:59 +00:00 Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
7.5
HIGH
CVE-2020-36277 2021-03-11 19:23 +00:00 Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
7.5
HIGH
CVE-2018-7440 2018-02-22 23:00 +00:00 An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.
9.8
CRITICAL
CVE-2018-7441 2018-02-22 23:00 +00:00 Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
7
HIGH
CVE-2018-7442 2018-02-22 23:00 +00:00 An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.
9.1
CRITICAL
CVE-2018-7247 2018-02-18 23:00 +00:00 An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact.
9.8
CRITICAL
CVE-2018-7186 2018-02-15 23:00 +00:00 Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.
9.8
CRITICAL
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.