CVE-2018-18718: Double Free
Published Oct 28, 2018
·Updated
An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the addthemesfromdir method in dlg-contact-sheet.c because of two successive calls of gfree, each of which frees the same buffer.
Affected Software
2 affected components
Gnome gThumb<=3.6.2
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Oct 28, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-18718.
2
What is the severity of CVE-2018-18718?
The severity of CVE-2018-18718 is high with a CVSS score of 7.8.
3
What is the affected software for CVE-2018-18718?
The affected software for CVE-2018-18718 is GNOME gThumb version up to 3.6.2 and Debian Linux version 8.0.
4
What is the vulnerability description of CVE-2018-18718?
CVE-2018-18718 is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c in gThumb.
5
Are there any references for CVE-2018-18718?
Yes, you can find references for CVE-2018-18718 at the following links: [1] https://gitlab.gnome.org/GNOME/gthumb/issues/18 [2] https://lists.debian.org/debian-lts-announce/2018/11/msg00002.html