Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.3

Adobe Acrobat: Heap Buffer Overflow in BMP Images

RLSA-2023:2589
Summary

Adobe Acrobat's autotrace feature can be exploited by malicious BMP images, potentially allowing an attacker to execute arbitrary code. This vulnerability affects users who use autotrace to convert images, and they should update their software to the latest version to prevent potential security risks.

What to do
  • Update autotrace to version 0:0.31.1-65.el9.
Affected software
Ecosystem VendorProductAffected versions
Rocky Linux:9 – autotrace < 0:0.31.1-65.el9
Fix: upgrade to 0:0.31.1-65.el9
Original title
Moderate: autotrace security update
Original description
AutoTrace is a program for converting bitmaps to vector graphics.

Security Fix(es):

* autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c (CVE-2022-32323)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.2 Release Notes linked from the References section.
osv CVSS3.1 7.3
Published: 28 Jun 2026 · Updated: 28 Jun 2026 · First seen: 28 Jun 2026