Source: imlib2
Version: 1.6.1-1
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for imlib2.

CVE-2020-12761[0]:
| modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow
| (with resultant invalid memory allocations and out-of-bounds reads)
| via an icon with many colors in its color map.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-12761
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12761
[1] 
https://git.enlightenment.org/legacy/imlib2.git/commit/?id=c95f938ff1effaf91729c050a0f1c8684da4

Regards,
Salvatore

Reply via email to