PT-2018-18754 · Netpbm+2 · Netpbm+2

Publicado

2018-03-25

·

Atualizado

2024-06-15

·

CVE-2018-8975

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netpbm versions prior to 10.81.03
Description The issue allows remote attackers to cause a denial of service, specifically a heap-based buffer over-read, via a crafted image file. This has been demonstrated using the pbmmask tool. The problem lies in the pm mallocarray2 function located in lib/util/mallocvar.c.
Recommendations For versions prior to 10.81.03, update to a version that includes the fix for this issue to prevent remote attackers from causing a denial of service. As a temporary workaround, consider restricting the use of the pm mallocarray2 function until a patch is available. Avoid processing crafted image files with the affected Netpbm versions to minimize the risk of exploitation.

Exploit

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1534
CVE-2018-8975
MGASA-2019-0183
OPENSUSE-SU-2019:1200-1
OPENSUSE-SU-2019_1200-1
OPENSUSE-SU-2024:11084-1
SUSE-SU-2019:0855-1
SUSE-SU-2019:1645-1
SUSE-SU-2019_0855-1

Produtos afetados

Alt Linux
Netpbm
Suse