Input validation error in afflib - CVE-2018-8050
Published: November 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the af_get_page() function in lib/afflib_pages.cpp. A remote attacker can pass a corrupted AFF image to the application and perform a denial of service (DoS) attack.
Affected software
Fedora
Ubuntu
afflib-tools (Ubuntu package)
libafflib0v5 (Ubuntu package)
afflib
How to mitigate CVE-2018-8050
afflib-tools (Ubuntu package) - update to Ubuntu Pro
libafflib0v5 (Ubuntu package) - update to Ubuntu Pro
afflib - addressed in versions 3.7.16-4.fc27, 3.7.16-4.fc28, 3.7.18-2.el7