CVE-2018-10112: Buffer Overflow
An issue was discovered in GEGL through 0.3.32. The gegltilebackendswapconstructed function in buffer/gegl-tile-backend-swap.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PNG file that is mishandled during a call to the bablformatgetbytesperpixel function in babl-format.c in babl 0.1.46.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10112?
CVE-2018-10112 is a vulnerability discovered in GEGL, which allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PNG file.
What is the severity of CVE-2018-10112?
The severity of CVE-2018-10112 is high with a CVSS score of 8.8.
What software versions are affected by CVE-2018-10112?
Versions up to and including 0.3.32 of GEGL are affected by CVE-2018-10112.
How can CVE-2018-10112 be exploited?
CVE-2018-10112 can be exploited by sending a malformed PNG file to the affected GEGL application.
Is there a fix for CVE-2018-10112?
Yes, updating GEGL to version 0.3.33 or higher can fix CVE-2018-10112.