Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
Adobe Illustrator autotrace heap-buffer overflow risk
RLSA-2023:3067
Summary
The autotrace feature in Adobe Illustrator can be exploited to cause the program to crash or behave unexpectedly. This issue can be triggered when the program is used to convert certain types of bitmap images to vector graphics. It's recommended to update to the latest version of Adobe Illustrator to fix this issue.
What to do
- Update autotrace to version 0:0.31.1-55.el8.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Rocky Linux:8 | – | autotrace |
< 0:0.31.1-55.el8 Fix: upgrade to 0:0.31.1-55.el8
|
Original title
Moderate: autotrace security update
Original description
AutoTrace is a program for converting bitmaps to vector graphics.
Security Fix(es):
* autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c (CVE-2022-32323)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.8 Release Notes linked from the References section.
Security Fix(es):
* autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c (CVE-2022-32323)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.8 Release Notes linked from the References section.
osv CVSS3.1
7.3
- https://errata.rockylinux.org/RLSA-2023:3067 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107471 Third Party Advisory
Published: 28 Jun 2026 · Updated: 28 Jun 2026 · First seen: 28 Jun 2026