Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7554

Опубликовано: 28 фев. 2018
Источник: debian
EPSS Низкий

Описание

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sam2premovedpackage
sam2pfixed0.49.2-3+deb8u2jessiepackage

Примечания

  • https://github.com/pts/sam2p/issues/29

  • https://github.com/pts/sam2p/commit/a6621e996f976912252018be8a8836ee6a966ee3

  • https://github.com/pts/sam2p/commit/118cb8102b767df4100d8a14184e44b33a822861

  • https://github.com/pts/sam2p/commit/1e43ec5fe34b009cb43f90a9d562442ca347cd75

  • https://github.com/pts/sam2p/commit/beea3bd8dd05a731fddfa447ff0bad19fe32c973

  • https://github.com/pts/sam2p/commit/47378716ab03d6b39ee959c949df551c643942f1

EPSS

Процентиль: 68%
0.00567
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
nvd
почти 8 лет назад

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
github
больше 3 лет назад

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
fstec
почти 8 лет назад

Уязвимость функции ReadImage утилиты для конвертации изображений Sam2p, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

EPSS

Процентиль: 68%
0.00567
Низкий