PT-2018-2597 · Libcaca+2 · Libcaca+2

Fgeeko

·

Published

2018-11-22

·

Updated

2025-01-13

·

CVE-2018-20545

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libcaca version 0.99.beta19
Description The issue is related to an integer overflow in the load image function, located in common-image.c, which can lead to an illegal WRITE memory access, particularly for 4bpp data. This can potentially allow a remote attacker to execute arbitrary code.
Recommendations For libcaca version 0.99.beta19, consider disabling the load image function until a patch is available to prevent potential exploitation. Restrict access to the common-image.c module to minimize the risk of exploitation. Avoid using the load image function for 4bpp data until the issue is resolved.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2019-01073
CVE-2018-20545
MGASA-2019-0050
OPENSUSE-SU-2019:1144-1
OPENSUSE-SU-2019_1144-1
OPENSUSE-SU-2024:10927-1
ROSA-SA-2025-2554
SUSE-SU-2019:0770-1
SUSE-SU-2019:2745-1
SUSE-SU-2019:2745-2
USN-3860-1
USN-3860-2

Affected Products

Suse
Ubuntu
Libcaca