CVE-2018-8975: Medium severity Netpbm Project Netpbm vulnerability
Published Mar 25, 2018
·Updated
The pmmallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Affected Software
1 affected component
Netpbm Project Netpbm<=10.81.03
Event History
Mar 25, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8975?
CVE-2018-8975 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-8975?
To fix CVE-2018-8975, update Netpbm to version 10.81.04 or later.
3
What types of attacks are possible with CVE-2018-8975?
CVE-2018-8975 allows remote attackers to cause heap-based buffer over-reads through crafted image files.
4
Which versions of Netpbm are affected by CVE-2018-8975?
Netpbm versions up to and including 10.81.03 are affected by CVE-2018-8975.
5
Is there a proof of concept for CVE-2018-8975?
Yes, there are proof of concept exploits available that demonstrate the vulnerability of CVE-2018-8975.