CVE-2016-5637: Libbpg Project Libbpg
High severity, CVSS 8.8. EPSS: 2.9% chance of exploitation in the next 30 days.
The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted BPG image, related to a "type confusion" issue.
Affected products
- Libbpg Project Libbpg: from 0.9.5, up to and including 0.9.7
Published 2016-07-15. Last modified 2026-06-17.