{"id":"CVE-2017-7263","details":"The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.","modified":"2026-03-14T09:26:29.068887Z","published":"2017-03-26T05:59:00.227Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/97112"},{"type":"FIX","url":"https://blogs.gentoo.org/ago/2017/03/03/potrace-heap-based-buffer-overflow-in-bm_readbody_bmp-bitmap_io-c-incomplete-fix-for-cve-2016-8698/"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7263.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"1.14"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}