{"id":"CVE-2017-8326","details":"libimageworsener.a in ImageWorsener before 1.3.1 has \"left shift cannot be represented in type int\" undefined behavior issues, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image, related to imagew-bmp.c and imagew-util.c.","modified":"2026-07-08T16:54:03.670688Z","published":"2017-04-29T20:59:00.227Z","references":[{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201706-06"},{"type":"FIX","url":"https://blogs.gentoo.org/ago/2017/04/27/imageworsener-two-left-shift/"},{"type":"FIX","url":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jsummers/imageworsener","events":[{"introduced":"0"},{"last_affected":"fbfb0d477fb459eaf2f8e0868b87be0739133bef"},{"fixed":"a00183107d4b84bc8a714290e824ca9c68dac738"}],"database_specific":{"cpe":"cpe:2.3:a:entropymine:imageworsener:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.3.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.3.0","1.2.0","1.1.0","1.0.0","0.9.10","0.9.9","0.9.8","0.9.6","0.9.5","0.9.4","0.9.3","0.9.2","0.9.1","0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8326.json","vanir_signatures_modified":"2026-07-08T16:54:03Z","vanir_signatures":[{"target":{"file":"src/imagew-util.c","function":"iw_get_i32le"},"deprecated":false,"digest":{"function_hash":"153372018570267176720890529744128300097","length":152},"id":"CVE-2017-8326-072ca17f","signature_type":"Function","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-util.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["211382068140858635723264930750222297643","74623404602380721082143941854266220485","311665602779919187967258793404899372785","107206791284567583672606954918344664305","257088163195196898418942225686201045500","5109589055673950353967322898565120969","90651403275263285140180861583988033656","112049071427257956028442059925739204302","290451180991792682115331820657291101986","217811011610079710549319264971119365773","332436195793507979418980662507776890796","189392913528077876008082108845946831285","60889062634335314999862160755453629227","249606105439490279252307014343075543658","262552228280410179634515138638278587596","47820839450512965121815608704523019066","288977080672119849944910846144152511069","152175791863095905972825302846173811676","128084072967889174587290167248752031330","82129459142966836391477747624971729466"]},"id":"CVE-2017-8326-0c466ce2"},{"target":{"function":"find_high_bit","file":"src/imagew-bmp.c"},"deprecated":false,"digest":{"function_hash":"82411948936977240340731491396693431493","length":155},"id":"CVE-2017-8326-4c4d3e32","signature_type":"Function","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738"},{"deprecated":false,"digest":{"line_hashes":["181748851845494149714177540211708913307","152741653319941007267633924695148100121","281335134186923838523040868135516544560","83592238665777084632954458967868577262","28062393793742210753734453004665313917","227228387043197736947039363170807686316","265797870266167928102076777201215611134","83592238665777084632954458967868577262"],"threshold":0.9},"id":"CVE-2017-8326-4e12e121","signature_type":"Line","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-bmp.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-util.c","function":"iw_get_ui16be"},"deprecated":false,"digest":{"function_hash":"45000162424615787546709958022296803818","length":80},"id":"CVE-2017-8326-5647e745"},{"deprecated":false,"digest":{"function_hash":"281648448375319185489296056759610539119","length":155},"id":"CVE-2017-8326-a52c4950","signature_type":"Function","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-bmp.c","function":"find_low_bit"}},{"digest":{"function_hash":"305678844318308512696710881984128495566","length":128},"id":"CVE-2017-8326-d29f7ff4","signature_type":"Function","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-util.c","function":"iw_get_ui32le"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"329948397021442492951336051598251890330","length":80},"id":"CVE-2017-8326-d474d85f","signature_type":"Function","signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-util.c","function":"iw_get_ui16le"}},{"signature_version":"v1","source":"https://github.com/jsummers/imageworsener/commit/a00183107d4b84bc8a714290e824ca9c68dac738","target":{"file":"src/imagew-util.c","function":"iw_get_ui32be"},"deprecated":false,"digest":{"function_hash":"148367599404440915797820707063652592366","length":128},"id":"CVE-2017-8326-f8a40477","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}