CVE-2018-20546
published 2018-12-28CVE-2018-20546: There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
PriorityP337high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
2.31%
81.6th percentile
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libcaca | < libcaca 0.99.beta19-2.1 (bookworm) | libcaca 0.99.beta19-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libcaca_project | libcaca | — | — |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.1 | 0.99.beta19-2.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta18-1ubuntu5.1 | 0.99.beta18-1ubuntu5.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.16.04.1 | 0.99.beta19-2ubuntu0.16.04.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.18.04.1 | 0.99.beta19-2ubuntu0.18.04.1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.1HIGH
vendor_debian8.1LOW
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8qg-9vxj-5pw7: There is an illegal READ memory access at caca/dither
ghsa_unreviewed·2022-05-13
CVE-2018-20546 [HIGH] CWE-190 GHSA-m8qg-9vxj-5pw7: There is an illegal READ memory access at caca/dither
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
OSV
libcaca vulnerabilities
osv·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
libcaca vulnerabilities
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
OSV
CVE-2018-20546: There is an illegal READ memory access at caca/dither
osv·2018-12-28·CVSS 8.1
CVE-2018-20546 [HIGH] CVE-2018-20546: There is an illegal READ memory access at caca/dither
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
USN-3860-1 fixed a vulnerability in libcaca. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update
Debian
CVE-2018-20546: libcaca - There is an illegal READ memory access at caca/dither.c (function get_rgba_defau...
vendor_debian·2018·CVSS 8.1
CVE-2018-20546 [HIGH] CVE-2018-20546: libcaca - There is an illegal READ memory access at caca/dither.c (function get_rgba_defau...
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Scope: local
bookworm: resolved (fixed in 0.99.beta19-2.1)
bullseye: resolved (fixed in 0.99.beta19-2.1)
forky: resolved (fixed in 0.99.beta19-2.1)
sid: resolved (fixed in 0.99.beta19-2.1)
trixie: resolved (fixed in 0.99.beta19-2.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20546 libcaca: out of bounds read in function get_rgba_default in caca/dither.c
bugzilla·2019-03-12·CVSS 8.1
CVE-2018-20546 [HIGH] CVE-2018-20546 libcaca: out of bounds read in function get_rgba_default in caca/dither.c
CVE-2018-20546 libcaca: out of bounds read in function get_rgba_default in caca/dither.c
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1652622
https://github.com/cacalabs/libcaca/issues/38
Upstream commit:
https://github.com/cacalabs/libcaca/commit/02a09ec9e5ed8981e7a810bfb6a0172dc24f0790
Discussion:
Created libcaca tracking bugs for this issue:
Affects: fedora-all [bug 1687858]
---
Created libcaca tracking bugs for this issue:
Affects: epel-all [bug 1687860]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent b
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
bugzilla·2019-03-12·CVSS 6.5
CVE-2018-20544 [MEDIUM] CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547 CVE-2018-20548 CVE-2018-20549 libcaca: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00033.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1652622https://github.com/cacalabs/libcaca/commit/1022d97496c7899e8641515af363381b31ae2f05https://github.com/cacalabs/libcaca/issues/38https://lists.debian.org/debian-lts-announce/2019/01/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PC7EGOEQ5C4OD66ZUJJIIYEXBTZOCMZX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSBCRN6EGQJUVOSD4OEEQ6XORHEM2CUL/https://usn.ubuntu.com/3860-1/https://usn.ubuntu.com/3860-2/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00033.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1652622https://github.com/cacalabs/libcaca/commit/1022d97496c7899e8641515af363381b31ae2f05https://github.com/cacalabs/libcaca/issues/38https://lists.debian.org/debian-lts-announce/2019/01/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PC7EGOEQ5C4OD66ZUJJIIYEXBTZOCMZX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSBCRN6EGQJUVOSD4OEEQ6XORHEM2CUL/https://usn.ubuntu.com/3860-1/https://usn.ubuntu.com/3860-2/
2018-12-28
Published