CVE-2018-12108: Input Validation
Published Jun 11, 2018
·Updated
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.
Affected Software
1 affected component
Dropbox Lepton=1.2.1
Remediation
Patch Available
Event History
Jun 11, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Dropbox Lepton 1.2.1?
The vulnerability ID for this issue in Dropbox Lepton 1.2.1 is CVE-2018-12108.
2
What is the severity of CVE-2018-12108?
The severity of CVE-2018-12108 is medium with a CVSS score of 5.5.
3
How does the validateAndCompress function in validation.cc in Dropbox Lepton allow attackers to cause a denial of service?
The validateAndCompress function in validation.cc in Dropbox Lepton allows remote attackers to cause a denial of service by exploiting a malformed file, resulting in a SIGFPE error and application crash.
4
What version of Dropbox Lepton is affected by CVE-2018-12108?
The version 1.2.1 of Dropbox Lepton is affected by CVE-2018-12108.
5
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following link: https://github.com/dropbox/lepton/issues/107