CVE-2018-14498
published 2019-03-07CVE-2018-14498: get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read…
PriorityP427medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.10%
86.3th percentile
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libjpeg-turbo | < libjpeg-turbo 1:2.0.5-1 (bookworm) | libjpeg-turbo 1:2.0.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libjpeg-turbo | libjpeg-turbo | <= 1.5.90 | — |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.4.2-0ubuntu3.3 | 1.4.2-0ubuntu3.3 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.5.2-0ubuntu5.18.04.3 | 1.5.2-0ubuntu5.18.04.3 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.3.0-0ubuntu2.1+esm2 | 1.3.0-0ubuntu2.1+esm2 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.4.2-0ubuntu3.4+esm1 | 1.4.2-0ubuntu3.4+esm1 |
| mozilla | mozjpeg | <= 3.3.1 | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libjpeg-turbo vulnerabilities
osv·2022-08-08·CVSS 7.5
CVE-2018-11813 [HIGH] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo was not properly handling EOF characters,
which could lead to excessive memory consumption through the execution of a
large loop. An attacker could possibly use this issue to cause a denial of
service. (CVE-2018-11813)
It was discovered that libjpeg-turbo was not properly performing bounds
check operations, which could lead to a heap-based buffer overread. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 14.04 ESM. (CVE-2018-14498)
It was discovered that libjpeg-turbo was not properly limiting the amount of
main memory being consumed by the system during decompression or multi-pass
comp
GHSA
GHSA-jg8v-w7gx-4g68: get_8bit_row in rdbmp
ghsa_unreviewed·2022-05-13
CVE-2018-14498 [MEDIUM] CWE-125 GHSA-jg8v-w7gx-4g68: get_8bit_row in rdbmp
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
OSV
libjpeg-turbo vulnerabilities
osv·2019-11-13·CVSS 6.5
CVE-2018-14498 [MEDIUM] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-14498)
It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 19.04. (CVE-2018-19664)
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 19.04. (CVE-2018-20330)
It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.
An attacker could possibly cause a denial of
OSV
CVE-2018-14498: get_8bit_row in rdbmp
osv·2019-03-07·CVSS 6.5
CVE-2018-14498 [MEDIUM] CVE-2018-14498: get_8bit_row in rdbmp
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2022-08-08·CVSS 7.5
CVE-2020-17541 [HIGH] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo was not properly handling EOF characters,
which could lead to excessive memory consumption through the execution of a
large loop. An attacker could possibly use this issue to cause a denial of
service. (CVE-2018-11813)
It was discovered that libjpeg-turbo was not properly performing bounds
check operations, which could lead to a heap-based buffer overread. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 14.04 ESM. (CVE-2018-14498)
It was discovered that libjpeg-turbo was not properly limiting the amount of
main memor
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2019-11-13·CVSS 6.5
CVE-2018-14498 [MEDIUM] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-14498)
It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 19.04. (CVE-2018-19664)
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 19.04. (CVE-2018-20330)
It was discovered that libjpeg-turbo incorrectly han
Red Hat
libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service
vendor_redhat·2018-07-20·CVSS 6.5
CVE-2018-14498 [MEDIUM] CWE-125 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service
libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Package: libjpeg-turbo (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2018-14498: libjpeg-turbo - get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3....
vendor_debian·2018·CVSS 6.5
CVE-2018-14498 [MEDIUM] CVE-2018-14498: libjpeg-turbo - get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3....
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14498 mingw-libjpeg-turbo: libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [epel-7]
bugzilla·2019-03-11·CVSS 6.5
CVE-2018-14498 [MEDIUM] CVE-2018-14498 mingw-libjpeg-turbo: libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [epel-7]
CVE-2018-14498 mingw-libjpeg-turbo: libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2018-14498 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service
bugzilla·2019-03-11·CVSS 6.5
CVE-2018-14498 [MEDIUM] CVE-2018-14498 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service
CVE-2018-14498 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Upstream patch:
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55
Upstream issue:
https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258
References:
https://github.com/mozilla/mozjpeg/issues/299
Discussion:
Created libjpeg-turbo tracking bugs for this issue:
Affects: fedora-28 [bug 1687428]
Created mingw-libjpe
Bugzilla
CVE-2018-14498 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [fedora-28]
bugzilla·2019-03-11·CVSS 6.5
CVE-2018-14498 [MEDIUM] CVE-2018-14498 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [fedora-28]
CVE-2018-14498 libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2018-14498 mingw-libjpeg-turbo: libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [fedora-28]
bugzilla·2019-03-11·CVSS 6.5
CVE-2018-14498 [MEDIUM] CVE-2018-14498 mingw-libjpeg-turbo: libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [fedora-28]
CVE-2018-14498 mingw-libjpeg-turbo: libjpeg-turbo: heap-based buffer over-read via crafted 8-bit BMP in get_8bit_row in rdbmp.c leads to denial of service [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM change
arXiv
Fuzzing: Randomness? Reasoning! Efficient Directed Fuzzing via Large Language Models
arxiv_fulltext·2025-06-30
Fuzzing: Randomness? Reasoning! Efficient Directed Fuzzing via Large Language Models
Large Language Model Assisted Directed Fuzzing:\ First, Then Fuzzing
Fuzzing: Randomness? Reasoning! \ Directed Fuzzing via Large Language Models
Xiaotao Feng
360 Security Technology Inc.
Beijing, China
[email protected]
Xiaogang Zhu
School of Computer and Mathematical Sciences
The University of Adelaide
Adelaide, SA, Australia
[email protected]
Kun Hu
School of Science
Edith Cowan University
Joondalup, WA, Australia
[email protected]
Jincheng Wang
360 Security Technology Inc.
Beijing, China
[email protected]
Yingjie Cao
360 Security Technology Inc.
Beijing, China
[email protected]
Guang Gong
360 Security Technology Inc.
Beijing, China
[email protected]
Jianfeng Pan
360 Security Technology Inc.
Beijing, China
[email protected]
## Abstrac
arXiv
Dissecting contact tracing apps in the Android platform
arxiv_fulltext·2021-05-21
Dissecting contact tracing apps in the Android platform
Dissecting contact tracing apps in the Android platform
[1]Vasileios Kouliaridis
[2]Georgios Kambourakis
[1]Efstratios Chatzoglou
[3]Dimitrios Geneiatakis
[4]Hua Wang
[1]Department of Information & Communication Systems Engineering, University of the Aegean, Greece
[2]European Commission, Joint Research Centre (JRC), 21027 Ispra (VA), Italy
[3]European Commission, Directorate-General for Informatics, 1000 Bruxelles/Brussel, Belgium
[4]Institute of Sustainable Industries and Liveable Cities, Victoria University, Melbourne, VIC 8001, Australia
This work is published in PLOS ONE, DOI: https://doi.org/10.1371/journal.pone.0251867.
Abstract: Contact tracing has historically been used to retard the spread of infectious diseases, but if it is exercised by hand in large-scale, it is known to b
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2019:2052https://access.redhat.com/errata/RHSA-2019:3705https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258https://github.com/mozilla/mozjpeg/issues/299https://lists.debian.org/debian-lts-announce/2019/03/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7YP4QUEYGHI4Q7GIAVFVKWQ7DJMBYLU/https://usn.ubuntu.com/4190-1/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2019:2052https://access.redhat.com/errata/RHSA-2019:3705https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258https://github.com/mozilla/mozjpeg/issues/299https://lists.debian.org/debian-lts-announce/2019/03/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7YP4QUEYGHI4Q7GIAVFVKWQ7DJMBYLU/https://usn.ubuntu.com/4190-1/
2019-03-07
Published