CVE-2018-10971: Medium severity flif vulnerability
Published May 10, 2018
·Updated
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file.
Affected Software
1 affected component
FLIF FLIF=0.3
Event History
May 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-10971.
2
What is the severity of CVE-2018-10971?
The severity of CVE-2018-10971 is medium, with a severity value of 5.5.
3
How does CVE-2018-10971 affect the Free Lossless Image Format (FLIF) version 0.3?
CVE-2018-10971 affects the Free Lossless Image Format (FLIF) version 0.3 by allowing remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file.
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-770.
5
How can I mitigate CVE-2018-10971?
To mitigate CVE-2018-10971, it is recommended to upgrade to a fixed version of FLIF that does not contain this vulnerability.