PT-2018-1091 · Sam2P · Sam2P

Fantasy7082

·

Published

2018-02-23

·

Updated

2020-12-17

·

CVE-2018-7554

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sam2p version 0.49.4
Description The issue is related to an invalid free in the ReadImage function in input-bmp.ci, which can cause a segmentation fault. A crafted input can lead to a denial of service or possibly other unspecified impacts. The vulnerability is associated with the use of memory after it has been freed, which can be exploited by a remote attacker to cause a denial of service or other effects.
Recommendations For sam2p version 0.49.4, consider disabling the ReadImage function in input-bmp.ci as a temporary workaround to minimize the risk of exploitation. Restrict the use of crafted inputs to prevent potential denial of service or other impacts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00487
CVE-2018-7554
DLA-1340-1
MGASA-2020-0459

Affected Products

Sam2P