PT-2018-18368 · Libvips+3 · Libvips+3
Published
2018-03-09
·
Updated
2025-01-17
·
CVE-2018-7998
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
libvips versions prior to 8.6.3
Description:
A NULL function pointer dereference issue was found in the
vips region generate function, which can be exploited by remote attackers using a crafted image file. This issue arises due to a race condition involving a failed delayed load and other worker threads, potentially leading to a denial of service or other unspecified impacts.Recommendations:
For versions prior to 8.6.3, update to version 8.6.3 or later to resolve the issue. As a temporary workaround, consider restricting the processing of image files from untrusted sources until the update is applied.
Exploit
Fix
DoS
Race Condition
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Ubuntu
Libvips