CVE-2018-20820: Integer Overflow
Published Apr 23, 2019
·Updated
readujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.
Affected Software
1 affected component
Dropbox Lepton=1.2.1
Remediation
Patch Available
Event History
Apr 23, 2019
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-20820.
2
What is the severity level of CVE-2018-20820?
The severity level of CVE-2018-20820 is medium.
3
How does CVE-2018-20820 affect Dropbox Lepton?
CVE-2018-20820 allows attackers to cause a denial-of-service in Dropbox Lepton version 1.2.1.
4
How can the denial-of-service be triggered in Dropbox Lepton?
The denial-of-service can be triggered by sending a crafted file to Dropbox Lepton.
5
Is there a fix available for CVE-2018-20820?
Yes, a fix for CVE-2018-20820 is available. Please refer to the references for more information.