First published: Fri Jul 20 2018(Updated: )
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libjpeg-turbo | <0:1.2.90-8.el7 | 0:1.2.90-8.el7 |
redhat/libjpeg-turbo | <0:1.5.3-10.el8 | 0:1.5.3-10.el8 |
Libjpeg-turbo Libjpeg-turbo | <=1.5.90 | |
Mozilla Mozjpeg | <=3.3.1 | |
Fedoraproject Fedora | =28 | |
Debian Debian Linux | =8.0 | |
openSUSE Leap | =15.0 | |
debian/libjpeg-turbo | 1:2.0.6-4 1:2.1.5-2 1:2.1.5-3 |
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14498 is a vulnerability in libjpeg-turbo and MozJPEG that allows attackers to cause a denial of service via a crafted 8-bit BMP.
CVE-2018-14498 works by exploiting a heap-based buffer over-read in the get_8bit_row function in rdbmp.c.
CVE-2018-14498 has a severity rating of 6.5 (medium).
To fix CVE-2018-14498 in libjpeg-turbo, you should update to version 1.5.90 or later.
To fix CVE-2018-14498 in MozJPEG, you should update to version 3.3.1 or later.