CVE-2024-48854

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*
cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:*
cpe:2.3:a:blackberry:qnx_software_development_platform:8.0:*:*:*:*:*:*:*

History

21 Jan 2025, 18:07

Type Values Removed Values Added
Summary
  • (es) Un error de un dígito en el códec de imagen TIFF en las versiones 8.0, 7.1 y 7.0 de QNX SDP podría permitir que un atacante no autenticado provoque una divulgación de información en el contexto del proceso que utiliza el códec de imagen.
References () https://support.blackberry.com/pkb/s/article/140334 - () https://support.blackberry.com/pkb/s/article/140334 - Vendor Advisory
First Time Blackberry
Blackberry qnx Software Development Platform
CPE cpe:2.3:a:blackberry:qnx_software_development_platform:8.0:*:*:*:*:*:*:*
cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*
cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:*

14 Jan 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 19:15

Updated : 2025-01-21 18:07


NVD link : CVE-2024-48854

Mitre link : CVE-2024-48854

CVE.ORG link : CVE-2024-48854


JSON object : View

Products Affected

blackberry

  • qnx_software_development_platform
CWE
CWE-193

Off-by-one Error