Mapbox is vulnerable to Integer Overflow
High severity
GitHub Reviewed
Published
Aug 17, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
< 10.6.1
Patched versions
10.6.1
Description
Published by the National Vulnerability Database
Aug 16, 2022
Published to the GitHub Advisory Database
Aug 17, 2022
Reviewed
Nov 22, 2022
Last updated
Feb 3, 2023
An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.
References