CVE-2018-7998
published 2018-03-09CVE-2018-7998: In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote…
PriorityP433high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
1.85%
76.9th percentile
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | vips | < vips 8.4.5-2 (bookworm) | vips 8.4.5-2 (bookworm) |
| libvips | libvips | < 8.6.3 | 8.6.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
VIPS vulnerabilities
vendor_ubuntu·2023-10-18·CVSS 7.5
CVE-2020-20739 [HIGH] VIPS vulnerabilities
Title: VIPS vulnerabilities
Summary: Several security issues were fixed in VIPS.
Ziqiang Gu discovered that VIPS could be made to dereference a NULL
pointer. If a user or automated system were tricked into processing
a specially crafted input image file, an attacker could possibly use
this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-7998)
It was discovered that VIPS did not properly handle uninitialized memory
locations when processing corrupted input image data. An attacker could
possibly use this issue to generate output images that expose sensitive
information. This issue only affected Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2019-6976)
It was discovered that VIPS did not properly manage memory due to an
uninitiali
Debian
CVE-2018-7998: vips - In libvips before 8.6.3, a NULL function pointer dereference vulnerability was f...
vendor_debian·2018·CVSS 7.5
CVE-2018-7998 [HIGH] CVE-2018-7998: vips - In libvips before 8.6.3, a NULL function pointer dereference vulnerability was f...
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.
Scope: local
bookworm: resolved (fixed in 8.4.5-2)
bullseye: resolved (fixed in 8.4.5-2)
forky: resolved (fixed in 8.4.5-2)
sid: resolved (fixed in 8.4.5-2)
trixie: resolved (fixed in 8.4.5-2)
OSV
vips vulnerabilities
osv·2023-10-18·CVSS 7.5
CVE-2018-7998 [HIGH] vips vulnerabilities
vips vulnerabilities
Ziqiang Gu discovered that VIPS could be made to dereference a NULL
pointer. If a user or automated system were tricked into processing
a specially crafted input image file, an attacker could possibly use
this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-7998)
It was discovered that VIPS did not properly handle uninitialized memory
locations when processing corrupted input image data. An attacker could
possibly use this issue to generate output images that expose sensitive
information. This issue only affected Ubuntu 16.04 LTS
and Ubuntu 18.04 LTS. (CVE-2019-6976)
It was discovered that VIPS did not properly manage memory due to an
uninitialized variable. If a user or automated system were tricked into
GHSA
GHSA-qvpx-7hqq-8g4f: In libvips before 8
ghsa_unreviewed·2022-05-14
CVE-2018-7998 [HIGH] CWE-362 GHSA-qvpx-7hqq-8g4f: In libvips before 8
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.
OSV
CVE-2018-7998: In libvips before 8
osv·2018-03-09·CVSS 7.5
CVE-2018-7998 [HIGH] CVE-2018-7998: In libvips before 8
In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jcupitt/libvips/commit/20d840e6da15c1574b3ed998bc92f91d1e36c2a5https://github.com/jcupitt/libvips/issues/893https://lists.debian.org/debian-lts-announce/2018/03/msg00009.htmlhttps://github.com/jcupitt/libvips/commit/20d840e6da15c1574b3ed998bc92f91d1e36c2a5https://github.com/jcupitt/libvips/issues/893https://lists.debian.org/debian-lts-announce/2018/03/msg00009.html
2018-03-09
Published