First published: Sat Apr 14 2018(Updated: )
An issue was discovered in GEGL through 0.3.32. The gegl_buffer_iterate_read_simple function in buffer/gegl-buffer-access.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PPM file, related to improper restrictions on memory allocation in the ppm_load_read_header function in operations/external/ppm-load.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gegl Gegl | <=0.3.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10114 is high, with a severity value of 8.8.
CVE-2018-10114 affects GEGL versions up to 0.3.32.
CVE-2018-10114 can result in a denial of service (write access violation) or possibly have unspecified other impact on the affected system.
CVE-2018-10114 can be exploited by remote attackers through a malformed PPM file.
At the time of writing, there is no known fix or patch available for CVE-2018-10114. It is recommended to update to a version of GEGL that is not affected by this vulnerability, if available.