Improper Input Validation in QNX SDP Image Codec Vulnerability
CVE-2024-48858

7.5HIGH

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
14 January 2025

What is CVE-2024-48858?

The PCX image codec in QNX Software Development Platform (SDP) contains an improper input validation issue which may allow an unauthenticated attacker to trigger a denial-of-service condition. This flaw affects multiple versions of QNX SDP, including 8.0, 7.1, and 7.0, compromising the integrity of the processes utilizing the image codec, ultimately impacting system stability and availability.

Affected Version(s)

QNX Software Development Platform (SDP) 8.0, 7.1 and 7.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.