An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process.
The vulnerability (CWE-1287 — improper input data validation) resides in the component responsible for processing SGI format images. An attacker can provide a specially crafted SGI image file that will not be properly validated by the codec. This results in potential code execution in the context of the image processing process or leads to a denial-of-service state.
An attacker can execute arbitrary code in the context of the image processing process or cause its crash (denial-of-service). The scope of the vulnerability includes confidentiality, integrity, and system availability at a critical level.
Patches available from the manufacturer should be applied in accordance with the references — detailed information about updates is available in the BlackBerry support article at https://support.blackberry.com/pkb/s/article/139914.
BlackBerry QNX Software Development Platform (QNX SDP) in versions 6.6, 7.0, and 7.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HBlackberry Qnx Software Development Platform
APPBlackberry6.6.0 – 8.0 (excl.)
Related vulnerabilities
Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS
Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS
RCE w kodeku obrazów BMP w BlackBerry QNX SDP
Integer overflow w calloc() w BlackBerry QNX — RCE i DoS
RCE i ujawnienie informacji w serwerze slinger — BlackBerry QNX SDP