CVE-2018-20545
published 2018-12-28CVE-2018-20545: There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.39%
82.1th percentile
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libcaca | < libcaca 0.99.beta19-2.1 (bookworm) | libcaca 0.99.beta19-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libcaca_project | libcaca | — | — |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta18-1ubuntu5.1 | 0.99.beta18-1ubuntu5.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.16.04.1 | 0.99.beta19-2ubuntu0.16.04.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.18.04.1 | 0.99.beta19-2ubuntu0.18.04.1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
USN-3860-1 fixed a vulnerability in libcaca. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update
Debian
CVE-2018-20545: libcaca - There is an illegal WRITE memory access at common-image.c (function load_image) ...
vendor_debian·2018·CVSS 8.8
CVE-2018-20545 [HIGH] CVE-2018-20545: libcaca - There is an illegal WRITE memory access at common-image.c (function load_image) ...
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
Scope: local
bookworm: resolved (fixed in 0.99.beta19-2.1)
bullseye: resolved (fixed in 0.99.beta19-2.1)
forky: resolved (fixed in 0.99.beta19-2.1)
sid: resolved (fixed in 0.99.beta19-2.1)
trixie: resolved (fixed in 0.99.beta19-2.1)
GHSA
GHSA-3638-4f56-qcf5: There is an illegal WRITE memory access at common-image
ghsa_unreviewed·2022-05-13
CVE-2018-20545 [HIGH] CWE-190 GHSA-3638-4f56-qcf5: There is an illegal WRITE memory access at common-image
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
OSV
libcaca vulnerabilities
osv·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
libcaca vulnerabilities
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
OSV
CVE-2018-20545: There is an illegal WRITE memory access at common-image
osv·2018-12-28·CVSS 8.8
CVE-2018-20545 [HIGH] CVE-2018-20545: There is an illegal WRITE memory access at common-image
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20545 libcaca: out of bounds write in function load_image in common-image.c
bugzilla·2019-03-12·CVSS 8.8
CVE-2018-20545 [HIGH] CVE-2018-20545 libcaca: out of bounds write in function load_image in common-image.c
CVE-2018-20545 libcaca: out of bounds write in function load_image in common-image.c
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1652621
https://github.com/cacalabs/libcaca/issues/37
Upstream commit:
https://github.com/cacalabs/libcaca/commit/3e52dabe3e64dc50f4422effe364a1457a8a8592
Discussion:
Created libcaca tracking bugs for this issue:
Affects: fedora-all [bug 1687858]
---
Created libcaca tracking bugs for this issue:
Affects: epel-all [bug 1687860]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of t
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00033.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1652621https://github.com/cacalabs/libcaca/commit/3e52dabe3e64dc50f4422effe364a1457a8a8592https://github.com/cacalabs/libcaca/issues/37https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PC7EGOEQ5C4OD66ZUJJIIYEXBTZOCMZX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSBCRN6EGQJUVOSD4OEEQ6XORHEM2CUL/https://usn.ubuntu.com/3860-1/https://usn.ubuntu.com/3860-2/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00033.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1652621https://github.com/cacalabs/libcaca/commit/3e52dabe3e64dc50f4422effe364a1457a8a8592https://github.com/cacalabs/libcaca/issues/37https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PC7EGOEQ5C4OD66ZUJJIIYEXBTZOCMZX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSBCRN6EGQJUVOSD4OEEQ6XORHEM2CUL/https://usn.ubuntu.com/3860-1/https://usn.ubuntu.com/3860-2/
2018-12-28
Published