First published: Wed Jun 06 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libjpeg-turbo | <0:1.2.90-8.el7 | 0:1.2.90-8.el7 |
Ijg Libjpeg | =9c | |
debian/libjpeg-turbo | 1:2.0.6-4 1:2.1.5-2 1:2.1.5-3 | |
debian/libjpeg9 | 1:9f-1 |
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/909a8cfc7bca9b2e6707425bdb74da997e8fa499
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2018-11813.
The severity of CVE-2018-11813 is high (7.5).
The software affected by CVE-2018-11813 includes libjpeg-turbo, libjpeg9, libjpeg6b, and libjpeg.
CVE-2018-11813 can cause a large loop in libjpeg 9c due to mishandling of EOF, which can lead to a denial-of-service condition.
More information about CVE-2018-11813 can be found in the following references: [link1](https://github.com/ChijinZ/security_advisories/blob/master/libjpeg-v9c/mail.pdf), [link2](https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9c), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1588804).