First published: Mon Nov 12 2018(Updated: )
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libwpd Project Libwpd | =0.10.2 | |
Redhat Enterprise Linux | =7.0 | |
SUSE SUSE Linux Enterprise Server | =11-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19208 is a vulnerability in libwpd 0.10.2 that allows for a denial of service attack due to a NULL pointer dereference in the WP6ContentListener::defineTable function.
CVE-2018-19208 has a severity rating of 6.5 out of 10.
The affected software versions are libwpd 0.10.2, Redhat Enterprise Linux 7.0, and Suse Linux Enterprise Server 11-sp4.
To fix CVE-2018-19208, you should update to a version of libwpd that is not affected by the vulnerability.
You can find more information about CVE-2018-19208 at the following references: [Reference 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1643752), [Reference 2](http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-19208), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1649415).