A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
https://github.com/autotrace/autotrace/pull/40
https://github.com/autotrace/autotrace/commits/master/src/input-bmp.c