CVE-2017-14636: SAM2P Project SAM2P

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. However, this also causes memory corruption because of an attempted write to the invalid d[0xfffffffe] array element.

Affected products

Published 2017-09-22. Last modified 2026-06-17.