PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory.
References
Link | Resource |
---|---|
https://gist.github.com/sunwithmoon/3f810c27d2e553f9d31bd7c50566f15b#file-cve-2023-44709 | Third Party Advisory |
https://github.com/sammycage/plutosvg/issues/7 | Exploit Issue Tracking |
https://gist.github.com/sunwithmoon/3f810c27d2e553f9d31bd7c50566f15b#file-cve-2023-44709 | Third Party Advisory |
https://github.com/sammycage/plutosvg/issues/7 | Exploit Issue Tracking |
Configurations
History
No history.
Information
Published : 2023-12-14 06:15
Updated : 2024-11-21 08:26
NVD link : CVE-2023-44709
Mitre link : CVE-2023-44709
CVE.ORG link : CVE-2023-44709
JSON object : View
Products Affected
sammycage
- plutosvg
CWE
CWE-190
Integer Overflow or Wraparound