CVE-2018-20546: Integer Overflow
Published Dec 28, 2018
·Updated
Last updated 25 August 2025
Other sources
There is an illegal READ memory access at caca/dither.c (function getrgbadefault) in libcaca 0.99.beta19 for the default bpp case.
— Launchpad
Affected Software
12 affected componentsFixes available
Libcaca Project Libcaca=0.99-beta19
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Debian Debian Linux=8.0
openSUSE Leap=15.0
debian/libcaca
0.99.beta19-2.20.99.beta19-2.2+deb11u10.99.beta20-30.99.beta20-50.99.beta20-6
Remediation
Patch Available
Event History
Dec 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·07:06 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:06 PM
Description
Data Sourced
via Debian·07:07 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20546?
CVE-2018-20546 has been classified as a high severity vulnerability due to the illegal READ memory access in libcaca.
2
How do I fix CVE-2018-20546?
To mitigate CVE-2018-20546, upgrade to libcaca versions 0.99.beta19-2.2, 0.99.beta20-3, or 0.99.beta20-5.
3
Which software is affected by CVE-2018-20546?
CVE-2018-20546 affects libcaca version 0.99.beta19 and prior versions in various Linux distributions.
4
What type of vulnerability is CVE-2018-20546?
CVE-2018-20546 is an illegal memory access vulnerability that can lead to potential denial of service or system instability.
5
Is there any public disclosure about CVE-2018-20546?
Yes, CVE-2018-20546 was publicly disclosed through several security announcements and database entries.