Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11214

Опубликовано: 16 мая 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

An out-of-bounds read vulnerability has been discovered in libjpeg-turbo when reading one row of pixels of a PPM file. An attacker could use this flaw to crash the application and cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libjpegWill not fix
Red Hat Enterprise Linux 6libjpeg-turboWill not fix
Red Hat Enterprise Linux 8libjpeg-turboNot affected
Red Hat Enterprise Linux 7libjpeg-turboFixedRHSA-2019:205206.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1579980libjpeg: Segmentation fault in get_text_rgb_row function in rdppm.c

EPSS

Процентиль: 77%
0.01054
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

CVSS3: 6.5
debian
больше 7 лет назад

An issue was discovered in libjpeg 9a. The get_text_rgb_row function i ...

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

oracle-oval
больше 6 лет назад

ELSA-2019-2052: libjpeg-turbo security update (MODERATE)

EPSS

Процентиль: 77%
0.01054
Низкий

5.3 Medium

CVSS3