CVE-2018-11212: Divide by Zero
An issue was discovered in libjpeg 9a and 9d. The allocsarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
Other sources
An issue was discovered in libjpeg version 9a. The allocsarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
References: https://github.com/ChijinZ/securityadvisories/tree/master/libjpeg-v9a
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-11212?
CVE-2018-11212 is a vulnerability in libjpeg 9a and 9d that allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
How severe is CVE-2018-11212?
CVE-2018-11212 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2018-11212?
The vulnerability affects libjpeg 9a, libjpeg 9d, libjpeg-turbo 1.5.2-2+deb10u1, libjpeg-turbo 2.0.6-4, and libjpeg-turbo 2.1.5-2.
How can I fix CVE-2018-11212?
To fix CVE-2018-11212, you should update to the latest version of libjpeg-turbo (1.5.2-2+deb10u1, 2.0.6-4, or 2.1.5-2) or libjpeg9 (9e-1) depending on your distribution.
Where can I find more information about CVE-2018-11212?
You can find more information about CVE-2018-11212 on the following links: - [GitHub Security Advisories](https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9a) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1579976) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1579974)