PT-2018-18368 · Libvips+3 · Libvips+3
Publicado
2018-03-09
·
Atualizado
2025-01-17
·
CVE-2018-7998
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
libvips versions prior to 8.6.3
Description:
A NULL function pointer dereference issue was found in the
vips region generate function, which can be exploited by remote attackers using a crafted image file. This issue arises due to a race condition involving a failed delayed load and other worker threads, potentially leading to a denial of service or other unspecified impacts.Recommendations:
For versions prior to 8.6.3, update to version 8.6.3 or later to resolve the issue. As a temporary workaround, consider restricting the processing of image files from untrusted sources until the update is applied.
Exploit
Correção
DoS
Race Condition
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Linuxmint
Ubuntu
Libvips