Posts Division By Zero | Deark
Post
Cancel

Division By Zero | Deark

Version: 1.5.7-1

Bug: Division by Zero

CVE: CVE-2021-28856

Description of the product:

A utility for file format and metadata analysis, data extraction, decompression, and image format decoding.

Summary:

An issue was discovered in Deark v1.5.7-1. A specially crafted input file can cause a division by zero in (src/fmtutil.c: 1621) because of the value of bi→pixelsize.

Fix:

https://github.com/jsummers/deark/commit/62acb7753b0e3c0d3ab3c15057b0a65222313334

This post is licensed under CC BY 4.0 by the author.