Input validation error in libjpeg - CVE-2018-11213

 

Input validation error in libjpeg - CVE-2018-11213

Published: January 13, 2020


Vulnerability identifier: #VU24196
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11213
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the get_text_gray_row() function in rdppm.c. A remote attacker can create a specially crafted image, trick the victim into opening it with software that uses the affected version of libjpeg, and perform a denial of service attack.


Affected software

libjpeg
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Ubuntu
Autodesk Infraworks
Data Computing Appliance (DCA)
libjpeg62 (Ubuntu package)

How to mitigate CVE-2018-11213

Install updates from vendor's website.

libjpeg - update to 9b
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Data Computing Appliance (DCA) - update to 4.3.0.0
libjpeg62 (Ubuntu package) - update to 6 b14ubuntu1+esm1

External References

Related Security Bulletins