CVE-2017-7263: Potrace Project Potrace
High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.
The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.
Affected products
- Potrace Project Potrace: version 1.14 only
Published 2017-03-26. Last modified 2026-06-17.