NULL pointer dereference in libvips - CVE-2018-7998
Published: October 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the vips_region_generate() function in region.c in the libvips library. A remote attacker can pass specially crafted input to the library and perform a denial of service (DoS) attack.
Affected software
Ubuntu
gir1.2-vips-8.0 (Ubuntu package)
libvips-tools (Ubuntu package)
libvips42 (Ubuntu package)
python-vipscc (Ubuntu package)
How to mitigate CVE-2018-7998
gir1.2-vips-8.0 (Ubuntu package) - update to Ubuntu Pro
libvips-tools (Ubuntu package) - update to Ubuntu Pro
libvips42 (Ubuntu package) - update to Ubuntu Pro
python-vipscc (Ubuntu package) - update to Ubuntu Pro