Heap-Based Buffer Over-Read Vulnerability in CImg by D.Tschump
CVE-2018-7639
7.8HIGH
What is CVE-2018-7639?
A vulnerability has been identified in CImg version 220, which allows for a heap-based buffer over-read during the loading of specially crafted BMP images. This flaw occurs specifically in the load_bmp function within the CImg.h file, affecting scenarios that handle images with a color depth of 16 bits. Exposing systems to this vulnerability may lead to unauthorized access or manipulation of sensitive data during the image processing operations.