PT-2024-20948 · Hugin+1 · Hugin+1

·

CVE-2024-25446

·

Published

2024-02-09

·

Updated

2024-02-20

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hugin version 2022.0.0
Description An issue in the HuginBase::PTools::setDestImage function allows attackers to cause a heap buffer overflow via parsing a crafted image.
Recommendations For Hugin version 2022.0.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the setDestImage function until a patch is available. Avoid parsing crafted images to minimize the risk of exploitation.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25446
OPENSUSE-SU-2024:0047-1

Affected Products

Debian
Hugin