---
cve: "CVE-2024-48854"
severity: "MEDIUM"
cvss: 5.3
epss: "37%"
vendor: "BlackBerry"
kev: false
exploited: false
published: "2025-01-14 19:15:31"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T13:50:09+02:00"
---

# CVE-2024-48854

> 5.3 MEDIUM

## Beschreibung

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.blackberry.com/pkb/s/article/140334>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-48854) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
