CRITICAL🇵🇱 Wersja polska

CVE-2025-2474

CVSS 9.8v3.1pub. 2025-06-10upd. 2025-12-01

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.

🤖 AI Analysis
How it works

The vulnerability consists of improper input data handling by the PCX image codec — a specially crafted PCX file can cause data to be written outside the allocated memory buffer (out-of-bounds write, CWE-787). An attacker without any privileges can deliver a malicious image file to an application using the vulnerable codec. Depending on the process execution context, the exploit can lead to arbitrary code execution or abnormal process termination.

Impact

An attacker can execute arbitrary code in the context of a process using the vulnerable PCX image codec, which may result in taking control of a system component, or trigger a denial of service (DoS) condition causing the process to crash.

Mitigation & patch

Patches available from the vendor should be applied according to the references (https://support.blackberry.com/pkb/s/article/140646). Until the fix is deployed, it is recommended to restrict processing of untrusted PCX image files by applications based on QNX SDP and minimize exposure of vulnerable components to untrusted input data.

Who is affected

BlackBerry QNX Software Development Platform (SDP) in versions 8.0, 7.1, and 7.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Blackberry Qnx Software Development Platform

    APP
    Blackberry
    7.07.18.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassMemory
CWE
References

Related vulnerabilities

CVE-2024-48856CRITICAL9.8PL ✓same product

Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS

CVE-2024-35213CRITICAL9.0PL ✓same product

Podatność improper input validation w SGI Image Codec QNX SDP

CVE-2021-32024CRITICAL9.8PL ✓same product

RCE w kodeku obrazów BMP w BlackBerry QNX SDP

CVE-2021-22156CRITICAL9.0PL ✓same product

Integer overflow w calloc() w BlackBerry QNX — RCE i DoS

CVE-2020-6932CRITICAL10.0PL ✓same product

RCE i ujawnienie informacji w serwerze slinger — BlackBerry QNX SDP