PT-2018-18754 · Netpbm+2 · Netpbm+2

Published

2018-03-25

·

Updated

2024-06-15

·

CVE-2018-8975

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netpbm versions prior to 10.81.03
Description The issue allows remote attackers to cause a denial of service, specifically a heap-based buffer over-read, via a crafted image file. This has been demonstrated using the pbmmask tool. The problem lies in the pm mallocarray2 function located in lib/util/mallocvar.c.
Recommendations For versions prior to 10.81.03, update to a version that includes the fix for this issue to prevent remote attackers from causing a denial of service. As a temporary workaround, consider restricting the use of the pm mallocarray2 function until a patch is available. Avoid processing crafted image files with the affected Netpbm versions to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1534
CVE-2018-8975
MGASA-2019-0183
OPENSUSE-SU-2019:1200-1
OPENSUSE-SU-2019_1200-1
OPENSUSE-SU-2024:11084-1
SUSE-SU-2019:0855-1
SUSE-SU-2019:1645-1
SUSE-SU-2019_0855-1

Affected Products

Alt Linux
Netpbm
Suse