Out-of-bounds Read Vulnerability in QNX SDP Image Codec
CVE-2024-48855

5.3MEDIUM

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
14 January 2025

What is CVE-2024-48855?

An out-of-bounds read vulnerability found in the TIFF image codec within QNX SDP versions 8.0, 7.1, and 7.0 can be exploited by unauthenticated attackers. This issue may lead to information disclosure during the operation of the image codec, potentially exposing sensitive data that could impact the integrity and confidentiality of the affected systems.

Affected Version(s)

QNX Software Development Platform (SDP) 8.0, 7.1 and 7.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.