PT-2018-9687 · Gnome+2 · Gegl+3
Xqx
·
Publicado
2018-04-14
·
Atualizado
2018-05-17
·
CVE-2018-10112
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
GEGL versions prior to 0.3.32
babl version 0.1.46
Description:
An issue in GEGL and babl allows remote attackers to cause a denial of service or possibly have other unspecified impacts via a malformed PNG file. This occurs during a call to the
babl format get bytes per pixel function in babl-format.c when the gegl tile backend swap constructed function in gegl-tile-backend-swap.c mishandles the file.Recommendations:
For GEGL versions prior to 0.3.32, update to a version newer than 0.3.32 to resolve the issue.
For babl version 0.1.46, consider restricting the use of the
babl format get bytes per pixel function until a patch is available.Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Gegl
Babl