Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14498

Опубликовано: 07 мар. 2019
Источник: debian
EPSS Низкий

Описание

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libjpeg-turbofixed1:2.0.5-1package
libjpeg-turbofixed1:1.5.2-2+deb10u1busterpackage
mozjpegitppackage

Примечания

  • https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55

  • https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258

  • https://github.com/mozilla/mozjpeg/issues/299

EPSS

Процентиль: 60%
0.00391
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 4.4
redhat
больше 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 6.5
nvd
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

rocky
больше 6 лет назад

Moderate: libjpeg-turbo security update

CVSS3: 6.5
github
больше 3 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

EPSS

Процентиль: 60%
0.00391
Низкий