CRITICAL🇵🇱 Wersja polska

CVE-2024-35213

CVSS 9.0v3.1pub. 2024-06-11upd. 2025-12-01

An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process.

🤖 AI Analysis
How it works

The vulnerability (CWE-1287 — improper input data validation) resides in the component responsible for processing SGI format images. An attacker can provide a specially crafted SGI image file that will not be properly validated by the codec. This results in potential code execution in the context of the image processing process or leads to a denial-of-service state.

Impact

An attacker can execute arbitrary code in the context of the image processing process or cause its crash (denial-of-service). The scope of the vulnerability includes confidentiality, integrity, and system availability at a critical level.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references — detailed information about updates is available in the BlackBerry support article at https://support.blackberry.com/pkb/s/article/139914.

Who is affected

BlackBerry QNX Software Development Platform (QNX SDP) in versions 6.6, 7.0, and 7.1.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Blackberry Qnx Software Development Platform

    APP
    Blackberry
    6.6.0 – 8.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-2474CRITICAL9.8PL ✓same product

Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS

CVE-2024-48856CRITICAL9.8PL ✓same product

Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS

CVE-2021-32024CRITICAL9.8PL ✓same product

RCE w kodeku obrazów BMP w BlackBerry QNX SDP

CVE-2021-22156CRITICAL9.0PL ✓same product

Integer overflow w calloc() w BlackBerry QNX — RCE i DoS

CVE-2020-6932CRITICAL10.0PL ✓same product

RCE i ujawnienie informacji w serwerze slinger — BlackBerry QNX SDP