CVE-2018-7186: Buffer Overflow
Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7186?
CVE-2018-7186 has a high severity due to its potential to cause a stack-based buffer overflow, leading to denial of service.
How do I fix CVE-2018-7186?
To fix CVE-2018-7186, upgrade to Leptonica version 1.75.3 or later.
What software is affected by CVE-2018-7186?
CVE-2018-7186 affects Leptonica versions prior to 1.75.3 and Debian 7.0.
What action can remote attackers perform through CVE-2018-7186?
Remote attackers can exploit CVE-2018-7186 to execute a stack-based buffer overflow.
Is there a known workaround for CVE-2018-7186?
There are no known workarounds for CVE-2018-7186; the recommended solution is to update the affected software.