CVE-2018-11213Out-of-bounds Read in Libjpeg

CWE-125Out-of-bounds Read16 documents8 sources
Severity
6.5MEDIUMNVD
EPSS
0.9%
top 24.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateJun 30

Description

An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Debianlibjpeg-turbo/libjpeg-turbo< 1:1.4.2-1+3
NVDijg/libjpeg9a

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.10, 18.04

🔴Vulnerability Details

4
GHSA
GHSA-p54x-fvh8-55xx: An issue was discovered in libjpeg 9a2022-05-13
OSV
libjpeg9 vulnerabilities2022-03-23
CVEList
CVE-2018-11213: An issue was discovered in libjpeg 9a2018-05-16
OSV
CVE-2018-11213: An issue was discovered in libjpeg 9a2018-05-16

📋Vendor Advisories

7
Ubuntu
Libjpeg6b vulnerabilities2022-06-30
Ubuntu
Libjpeg6b vulnerabilities2022-06-30
Ubuntu
libjpeg9 vulnerabilities2022-03-23
Ubuntu
libjpeg-turbo vulnerabilities2018-07-10
Ubuntu
libjpeg-turbo vulnerabilities2018-07-09

💬Community

4
Bugzilla
CVE-2018-11212 CVE-2018-11213 CVE-2018-11214 mingw-libjpeg-turbo: various flaws [epel-7]2018-05-18
Bugzilla
CVE-2018-11212 CVE-2018-11213 CVE-2018-11214 libjpeg-turbo: various flaws [fedora-all]2018-05-18
Bugzilla
CVE-2018-11212 CVE-2018-11213 CVE-2018-11214 mingw-libjpeg-turbo: various flaws [fedora-all]2018-05-18
Bugzilla
CVE-2018-11213 libjpeg: Segmentation fault in get_text_gray_row function in rdppm.c2018-05-18
CVE-2018-11213 — Out-of-bounds Read in IJG Libjpeg | cvebase