First published: Fri Jun 19 2020(Updated: )
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <4.10.4 | |
Mattermost | >=5.1.0<5.1.2 | |
Mattermost | >=5.2.0<5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21250 has a high severity rating due to its potential to cause denial of service.
To fix CVE-2018-21250, upgrade Mattermost Server to version 5.2.2 or later, 5.1.2, or 4.10.4.
CVE-2018-21250 affects Mattermost Server versions before 5.2.2, 5.1.2, and 4.10.4.
CVE-2018-21250 describes a remote denial of service attack due to memory consumption caused by crafted image dimensions.
Yes, CVE-2018-21250 can be exploited remotely by attackers sending specially crafted images.