First published: Mon Dec 31 2018(Updated: )
ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ok-file-formats Project Ok-file-formats | <=2018-10-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20618 is a vulnerability in ok-file-formats that allows for a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
CVE-2018-20618 has a severity rating of 8.8 out of 10, which is considered high.
CVE-2018-20618 affects all versions of ok-file-formats up to and including version 2018-10-16.
To fix CVE-2018-20618, it is recommended to update ok-file-formats to a version beyond 2018-10-16.
More information about CVE-2018-20618 can be found at the following reference: [GitHub Issue](https://github.com/brackeen/ok-file-formats/issues/6)