Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.102
EPSS Ranking 92.7%