CVE-2018-10767: Buffer Overflow
Published May 6, 2018
·Updated
There is a stack-based buffer over-read in calling GLib in the function gxpsimagesguesscontenttype of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a ginputstreamread call. A crafted input will lead to a remote denial of service attack.
Affected Software
5 affected components
Gnome libgxps<=0.3.0
redhat Ansible Tower=3.3
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Event History
May 6, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 9, 2018
Data Sourced
via Red Hat·04:31 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-10767?
CVE-2018-10767 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2018-10767?
To fix CVE-2018-10767, update libgxps to version 0.3.1 or later.
3
What causes CVE-2018-10767?
CVE-2018-10767 is caused by a stack-based buffer over-read due to negative return values from a g_input_stream_read call.
4
Which software is affected by CVE-2018-10767?
CVE-2018-10767 affects versions of libgxps up to 0.3.0, among other software related to Red Hat products.
5
Can CVE-2018-10767 lead to a remote attack?
Yes, CVE-2018-10767 can lead to a remote denial of service attack.