CVE-2018-10111: Buffer Overflow
Published Apr 14, 2018
·Updated
An issue was discovered in GEGL through 0.3.32. The renderrectangle function in process/gegl-processor.c has unbounded memory allocation, leading to a denial of service (application crash) upon allocation failure.
Affected Software
1 affected component
GEGL GEGL<=0.3.32
Event History
Apr 14, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-10111?
CVE-2018-10111 is a vulnerability discovered in GEGL through version 0.3.32 that allows an unbounded memory allocation, leading to an application crash.
2
What software is affected by CVE-2018-10111?
GEGL versions up to 0.3.32 are affected by CVE-2018-10111.
3
How severe is CVE-2018-10111?
CVE-2018-10111 has a severity rating of high, with a CVSS score of 7.5.
4
How can I fix CVE-2018-10111?
To fix CVE-2018-10111, it is recommended to update GEGL to version 0.3.33 or later.
5
Where can I find more information about CVE-2018-10111?
More information about CVE-2018-10111 can be found at the following link: [https://github.com/xiaoqx/pocs/tree/master/gegl]