Versio.io

CVE-2018-11212

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 16-05-2018 07:29
Last modified: - 20-04-2022 02:15
Total changes: - 2

Description

An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.

Common Vulnerability Scoring System (CVSS)

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
None
Confidentiality
None
Integrity
None
Privileges required
Unchanged
Scope
Required
User interaction
6.5
Base score
2.8
3.6
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=ijg AND product=libjpeg AND version=9a
OR
vendor=Debian AND product=debian_linux AND version=8.0
OR
vendor=canonical AND product=ubuntu_linux AND version=14.04 AND software_edition=lts
vendor=canonical AND product=ubuntu_linux AND version=16.04 AND software_edition=lts
vendor=canonical AND product=ubuntu_linux AND version=18.04 AND software_edition=lts
vendor=canonical AND product=ubuntu_linux AND version=12.04 AND software_edition=esm
OR
vendor=netapp AND product=snapmanager AND target_software=oracle
vendor=netapp AND product=oncommand_workflow_automation
vendor=netapp AND product=oncommand_unified_manager
vendor=netapp AND product=snapmanager AND target_software=sap
vendor=netapp AND product=oncommand_unified_manager AND target_software=windows AND versionStartIncluding=7.3
vendor=netapp AND product=oncommand_unified_manager AND target_software=vmware_vsphere AND versionStartIncluding=9.4
OR
vendor=oracle AND product=jdk AND version=1.8.0 AND update=update192
vendor=oracle AND product=jdk AND version=1.7.0 AND update=update201
vendor=oracle AND product=jre AND version=8.0 AND update=update_191
vendor=oracle AND product=jdk AND version=11.0.1
OR
vendor=Red Hat Enterprise Linux AND product=satellite AND version=5.8
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_desktop AND version=6.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_desktop AND version=7.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_workstation AND version=6.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_workstation AND version=7.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server AND version=6.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server AND version=7.0
OR
vendor=opensuse AND product=leap AND version=15.0
 

Reference

 


Keywords

NVD

 

CVE-2018-11212

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.