{"id":"CVE-2017-7448","details":"The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.","modified":"2026-07-08T16:53:34.183467Z","published":"2017-04-05T23:59:00.157Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/97490"},{"type":"FIX","url":"https://github.com/dropbox/lepton/commit/7789d99ac156adfd7bbf66e7824bd3e948a74cf7"},{"type":"EVIDENCE","url":"https://github.com/dropbox/lepton/issues/86"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dropbox/lepton","events":[{"introduced":"c378cbfa2daaa99e8828be7395013f94cedb1bcc"},{"last_affected":"c378cbfa2daaa99e8828be7395013f94cedb1bcc"},{"fixed":"7789d99ac156adfd7bbf66e7824bd3e948a74cf7"}],"database_specific":{"cpe":"cpe:2.3:a:dropbox:lepton:1.2.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.1"},{"last_affected":"1.2.1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7448.json","vanir_signatures_modified":"2026-07-08T16:53:34Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["104845311606380076568842677017325723916","199487273269160114457741564468247131006","157679577332504595206723670414743180066","338000704461876320734988242919132086596","40073391338326186465395942658324346847"],"threshold":0.9},"id":"CVE-2017-7448-910aacf3","signature_type":"Line","signature_version":"v1","source":"https://github.com/dropbox/lepton/commit/7789d99ac156adfd7bbf66e7824bd3e948a74cf7","target":{"file":"src/vp8/model/model.hh"}},{"target":{"file":"src/lepton/uncompressed_components.hh"},"deprecated":false,"digest":{"line_hashes":["300180288418872669232553092164351926291","301080161881238933121730163318626242666","141557665056054093696014674072908756801","290644006959424437078299616216229851174","29167694385379973089611876023557667337","7971325174013206209265610457947140027"],"threshold":0.9},"id":"CVE-2017-7448-9c5f61c0","signature_type":"Line","signature_version":"v1","source":"https://github.com/dropbox/lepton/commit/7789d99ac156adfd7bbf66e7824bd3e948a74cf7"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}