First published: Sun Mar 25 2018(Updated: )
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netpbm | <=10.81.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8975 is classified as a denial of service vulnerability.
To fix CVE-2018-8975, update Netpbm to version 10.81.04 or later.
CVE-2018-8975 allows remote attackers to cause heap-based buffer over-reads through crafted image files.
Netpbm versions up to and including 10.81.03 are affected by CVE-2018-8975.
Yes, there are proof of concept exploits available that demonstrate the vulnerability of CVE-2018-8975.