-
CVSS Score
-The vulnerable functions were identified directly from the vulnerability description and confirmed by the stack traces provided in the linked GitHub issues. Although commit details could not be fetched, the issue reports provide sufficient evidence of the vulnerable functions and their locations within the codebase. The functions imagetopnm, sycc444_to_rgb, color_esycc_to_rgb, and sycc422_to_rgb are directly implicated in NULL pointer dereferences. The function color_sycc_to_rgb is included as it's a direct caller of two of the vulnerable functions (sycc444_to_rgb and sycc422_to_rgb) and appears in the exploit stack traces.
A Semantic Attack on Google Gemini - Read the Latest Research