CVE-2025-2474 PUBLISHED

Vulnerability in PCX Image Codec Impacts QNX Software Development Platform

Assigner: blackberry
Reserved: 17.03.2025 Published: 10.06.2025 Updated: 10.06.2025

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor BlackBerry
Product QNX Software Development Platform (SDP)
Versions Default: unaffected
  • Version 8.0, 7.1 and 7.0 is affected

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE

Impacts

  • CAPEC-153 Input Data Manipulation