CVE-2018-7554: Use After Free
Published Feb 28, 2018
·Updated
There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
Affected Software
2 affected components
Sam2p Project Sam2p=0.49.4
Debian Debian Linux=7.0
Event History
Feb 28, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-7554?
CVE-2018-7554 is a vulnerability in sam2p 0.49.4 that allows a crafted input to cause a denial of service or other impacts.
2
What is the severity of CVE-2018-7554?
The severity of CVE-2018-7554 is critical, with a severity value of 9.8.
3
How can CVE-2018-7554 be exploited?
CVE-2018-7554 can be exploited by providing a crafted input to the ReadImage function in input-bmp.ci, which leads to a segmentation fault in sam2p 0.49.4.
4
Which software versions are affected by CVE-2018-7554?
sam2p version 0.49.4 and Debian Linux version 7.0 are affected by CVE-2018-7554.
5
Is there a fix for CVE-2018-7554?
Yes, there is a fix available for CVE-2018-7554. Please refer to the provided references for more information.