CVE-2018-20544
published 2018-12-28CVE-2018-20544: There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
PriorityP426medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.87%
77.2th percentile
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libcaca | < libcaca 0.99.beta19-2.1 (bookworm) | libcaca 0.99.beta19-2.1 (bookworm) |
| libcaca_project | libcaca | — | — |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta18-1ubuntu5.1 | 0.99.beta18-1ubuntu5.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.16.04.1 | 0.99.beta19-2ubuntu0.16.04.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.18.04.1 | 0.99.beta19-2ubuntu0.18.04.1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2chw-xgww-wgp9: There is floating point exception at caca/dither
ghsa_unreviewed·2022-05-14
CVE-2018-20544 [MEDIUM] CWE-369 GHSA-2chw-xgww-wgp9: There is floating point exception at caca/dither
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
OSV
libcaca vulnerabilities
osv·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
libcaca vulnerabilities
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
OSV
CVE-2018-20544: There is floating point exception at caca/dither
osv·2018-12-28·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544: There is floating point exception at caca/dither
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
USN-3860-1 fixed a vulnerability in libcaca. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update
Debian
CVE-2018-20544: libcaca - There is floating point exception at caca/dither.c (function caca_dither_bitmap)...
vendor_debian·2018·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544: libcaca - There is floating point exception at caca/dither.c (function caca_dither_bitmap)...
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
Scope: local
bookworm: resolved (fixed in 0.99.beta19-2.1)
bullseye: resolved (fixed in 0.99.beta19-2.1)
forky: resolved (fixed in 0.99.beta19-2.1)
sid: resolved (fixed in 0.99.beta19-2.1)
trixie: resolved (fixed in 0.99.beta19-2.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20544 libcaca: floating point exception in caca/dither.c
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 libcaca: floating point exception in caca/dither.c
CVE-2018-20544 libcaca: floating point exception in caca/dither.c
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1652627
https://github.com/cacalabs/libcaca/issues/36
Upstream commit:
https://github.com/cacalabs/libcaca/commit/84bd155087b93ab2d8d7cb5b1ac94ecd4cf4f93c
Discussion:
Created libcaca tracking bugs for this issue:
Affects: fedora-all [bug 1687858]
---
Created libcaca tracking bugs for this issue:
Affects: epel-all [bug 1687860]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community produc
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00033.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1652627https://lists.debian.org/debian-lts-announce/2019/01/msg00007.htmlhttps://usn.ubuntu.com/3860-1/https://usn.ubuntu.com/3860-2/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00033.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1652627https://lists.debian.org/debian-lts-announce/2019/01/msg00007.htmlhttps://usn.ubuntu.com/3860-1/https://usn.ubuntu.com/3860-2/
2018-12-28
Published