An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.
References
Link | Resource |
---|---|
https://github.com/mapbox/mapbox-maps-android/releases/tag/android-v10.6.1 | Release Notes Third Party Advisory |
Configurations
Information
Published : 2022-08-15 18:15
Updated : 2022-08-17 07:31
NVD link : CVE-2022-38216
Mitre link : CVE-2022-38216
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
mapbox
- maps_software_development_kit