Input validation error in libjpeg - CVE-2018-11214
Published: January 13, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the get_text_rgb_row() function in rdppm.c. A remote attacker can create a specially crafted image, trick the victim into opening it with software that uses the affected version of libjpeg, and perform a denial of service attack.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Ubuntu
Autodesk Infraworks
Data Computing Appliance (DCA)
libjpeg62 (Ubuntu package)
How to mitigate CVE-2018-11214
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Data Computing Appliance (DCA) - update to 4.3.0.0
libjpeg62 (Ubuntu package) - update to 6 b14ubuntu1+esm1