CVE-2018-11416Double Free in Project Jpegoptim

CWE-415Double Free8 documents6 sources
Severity
8.8HIGHNVD
EPSS
0.4%
top 40.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 14

Description

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-xg4r-75h7-2cgv: jpegoptim2022-05-14
OSV
CVE-2018-11416: jpegoptim2018-05-24

📋Vendor Advisories

1
Debian
CVE-2018-11416: jpegoptim - jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() ...2018

📄Research Papers

1
arXiv
An Empirical Study on Benchmarks of Artificial Software Vulnerabilities2020-03-21

💬Community

3
Bugzilla
CVE-2018-11416 jpegoptim: Invalid use of realloc() and free() allows denial of service2018-05-25
Bugzilla
CVE-2018-11416 jpegoptim: Invalid use of realloc() and free() allows denial of service [epel-all]2018-05-25
Bugzilla
CVE-2018-11416 jpegoptim: Invalid use of realloc() and free() allows denial of service [fedora-all]2018-05-25
CVE-2018-11416 — Double Free in Project Jpegoptim | cvebase