CVE-2018-7589: Double Free
An issue was discovered in CImg v.220. A double free in loadbmp in CImg.h occurs when loading a crafted bmp image.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cimgto a version that resolves this vulnerability.Fixed in 2.9.4+dfsg-2Fixed in 3.2.1+dfsg-1Fixed in 3.5.2+dfsg-1 - Upgrade
Upgrade
CImgto a version that resolves this vulnerability.Fixed in 220
Event History
Frequently Asked Questions
What is CVE-2018-7589?
CVE-2018-7589 is a vulnerability discovered in CImg v.220 that allows for a double free in load_bmp in CImg.h when loading a crafted bmp image.
What is the severity of CVE-2018-7589?
The severity of CVE-2018-7589 is high with a CVSS score of 7.8.
How does CVE-2018-7589 affect CImg?
CVE-2018-7589 affects CImg v.220 and potentially other versions as well.
How can I fix CVE-2018-7589?
To fix CVE-2018-7589, update to a version of CImg that includes the necessary security patches.
Where can I find more information about CVE-2018-7589?
You can find more information about CVE-2018-7589 on the MITRE CVE website and the GitHub repository for CImg.