First published: Thu Sep 21 2017(Updated: )
In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sam2p | =0.49.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14631 is classified as a high severity vulnerability due to the potential for a heap-based buffer overflow.
To fix CVE-2017-14631, update to a version of sam2p later than 0.49.3 that contains the necessary patches.
CVE-2017-14631 is caused by an integer signedness error in the pcxLoadRaster function leading to a heap-based buffer overflow.
CVE-2017-14631 specifically affects sam2p version 0.49.3.
Exploitation of CVE-2017-14631 could allow an attacker to execute arbitrary code or crash the application, compromising system integrity.