CVE-2018-20819: Buffer Overflow
Published Apr 23, 2019
·Updated
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size.
Affected Software
1 affected component
Dropbox Lepton=1.2.1
Remediation
Patch Available
Event History
Apr 23, 2019
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-20819.
2
What is the severity of CVE-2018-20819?
The severity of CVE-2018-20819 is high.
3
What software is affected by CVE-2018-20819?
The software affected by CVE-2018-20819 is Dropbox Lepton 1.2.1.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by crafting a jpg image file.
5
Is there a fix available for CVE-2018-20819?
No, there is no fix available for CVE-2018-20819 at the moment.