Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-14498

Опубликовано: 07 мар. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.5

Описание

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

РелизСтатусПримечание
bionic

released

1.5.2-0ubuntu5.18.04.3
cosmic

ignored

end of life
devel

not-affected

2.1.2-0ubuntu1
disco

not-affected

2.0.0-0ubuntu2
eoan

not-affected

2.0.1-0ubuntu2
esm-infra-legacy/trusty

released

1.3.0-0ubuntu2.1+esm2
esm-infra/bionic

released

1.5.2-0ubuntu5.18.04.3
esm-infra/focal

not-affected

2.0.3-0ubuntu1
esm-infra/xenial

released

1.4.2-0ubuntu3.3
focal

not-affected

2.0.3-0ubuntu1

Показывать по

EPSS

Процентиль: 60%
0.00391
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
redhat
больше 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 6.5
nvd
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 6.5
debian
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG th ...

rocky
больше 6 лет назад

Moderate: libjpeg-turbo security update

CVSS3: 6.5
github
больше 3 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

EPSS

Процентиль: 60%
0.00391
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Уязвимость CVE-2018-14498