It was found that converting any bmp image will cause out-of-bounds heap write in autotrace. CVE assignment: http://seclists.org/oss-sec/2016/q3/475 More details: https://blogs.gentoo.org/ago/2016/09/10/autotrace-heap-based-buffer-overflow-in-pstoedit_suffix_table_init-output-pstoedit-c/
Created autotrace tracking bugs for this issue: Affects: fedora-all [bug 1375256] Affects: epel-5 [bug 1375257]
This is only reproducible with experimental pstoedit backend which is currently not enabled in Fedora, but I am going to enable it.