First published: Mon Jun 11 2018(Updated: )
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dropbox Lepton | =1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in Dropbox Lepton 1.2.1 is CVE-2018-12108.
The severity of CVE-2018-12108 is medium with a CVSS score of 5.5.
The validateAndCompress function in validation.cc in Dropbox Lepton allows remote attackers to cause a denial of service by exploiting a malformed file, resulting in a SIGFPE error and application crash.
The version 1.2.1 of Dropbox Lepton is affected by CVE-2018-12108.
More information about this vulnerability can be found at the following link: https://github.com/dropbox/lepton/issues/107