CVE-2018-1152: Divide by Zero
Published Jun 18, 2018
·Updated
Last updated 25 August 2025
Other sources
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
— Launchpad
Affected Software
8 affected componentsFixes available
Libjpeg-turbo Libjpeg-turbo=1.5.90
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
debian/libjpeg-turbo
1:2.0.6-41:2.1.5-21:2.1.5-41:3.1.3-4
Remediation
Event History
Jun 18, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:47 PM
Description
Feb 18, 2026
Data Sourced
via Ubuntu·08:58 PM
RemedyDescriptionSeverityAffected Software
May 13, 2026
Data Sourced
via Debian·03:21 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-1152?
CVE-2018-1152 is a vulnerability in libjpeg-turbo 1.5.90 that can lead to a denial of service by causing a divide by zero when processing a crafted BMP image.
2
What is the severity of CVE-2018-1152?
CVE-2018-1152 has a severity rating of medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2018-1152?
The affected software versions include libjpeg-turbo 1.5.90.
4
How can I fix CVE-2018-1152?
To fix CVE-2018-1152, update libjpeg-turbo to version 1.5.2-2+deb10u1, 1.2.0.6-4, or 1.2.1.5-2.
5
Where can I find more information about CVE-2018-1152?
More information about CVE-2018-1152 can be found at the following references: [1] [2] [3]