CVE-2018-7588: High severity CImg cimg vulnerability
An issue was discovered in CImg v.220. A heap-based buffer over-read in loadbmp in CImg.h occurs when loading a crafted bmp image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cimgto a version that resolves this vulnerability.Fixed in 2.9.4+dfsg-2Fixed in 3.2.1+dfsg-1Fixed in 3.5.2+dfsg-1
Event History
Frequently Asked Questions
What is CVE-2018-7588?
CVE-2018-7588 is a vulnerability in CImg v.220 that allows for a heap-based buffer over-read when loading a crafted bmp image.
What is the severity of CVE-2018-7588?
CVE-2018-7588 has a severity rating of 7.8 (High).
How does CVE-2018-7588 impact CImg?
CVE-2018-7588 impacts CImg by causing a heap-based buffer over-read when loading a crafted bmp image.
What is the affected version of CImg?
The affected version of CImg is v.220.
How can I fix CVE-2018-7588?
To fix CVE-2018-7588, upgrade to CImg version 1.7.9+dfsg-2ubuntu0.18.04.1 (for Ubuntu), 1.7.9+dfsg-2ubuntu0.18.10.1 (for Ubuntu Cosmic), or 2.3.6+dfsg-1 (for Ubuntu upstream).