PT-2018-3434 · Cimg+2 · Cimg+2

Published

2018-03-01

·

Updated

2019-06-26

·

CVE-2018-7587

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CImg version 220
Description: A problem has been discovered that causes a denial of service (DoS) when loading a crafted bmp image, triggering an allocation failure in the load bmp function in CImg.h. The issue is related to a buffer overflow in memory, which can be exploited to cause a denial of service when a specially crafted bmp image is loaded.
Recommendations: For CImg version 220, consider disabling the load bmp function in CImg.h until a patch is available to prevent potential denial of service attacks. Restrict access to loading bmp images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01534
CVE-2018-7587
MGASA-2018-0438
USN-4039-1

Affected Products

Cimg
Debian
Ubuntu