8.8

CVE-2025-52930

Exploit
A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sail ≫ Sail Version 0.9.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.518
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Cisco Talos 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-680 Integer Overflow to Buffer Overflow

The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2221
Third Party Advisory
Exploit
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2221