In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
| Software | From | Fixed in |
|---|---|---|
| plib_project / plib | - | 1.8.5.x |
| debian / debian_linux | 9.0 | 9.0.x |
| fedoraproject / fedora | 34 | 34.x |
| fedoraproject / fedora | 35 | 35.x |
| fedoraproject / fedora | 36 | 36.x |
| fedoraproject / extra_packages_for_enterprise_linux | 7.0 | 7.0.x |
| fedoraproject / fedora | 37 | 37.x |