CVE-2018-11213: Medium severity IJG libjpeg vulnerability
An issue was discovered in libjpeg 9a. The gettextgrayrow function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
Other sources
An issue was discovered in libjpeg version 9a. The gettextgrayrow function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
References: https://github.com/ChijinZ/securityadvisories/tree/master/libjpeg-v9a
— Red Hat
An out-of-bound read vulnerability has been discovered in libjpeg-turbo when reading one row of pixels of a PGM file. An attacker could use this flaw to crash the application and cause a denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11213?
CVE-2018-11213 is an out-of-bound read vulnerability in libjpeg-turbo that allows remote attackers to crash the application and cause a denial of service.
What is the severity of CVE-2018-11213?
The severity of CVE-2018-11213 is medium with a CVSS score of 6.5.
How does CVE-2018-11213 affect libjpeg-turbo?
CVE-2018-11213 affects libjpeg-turbo version 1.2.90-8.el7.
How can I fix CVE-2018-11213 in libjpeg-turbo?
To fix CVE-2018-11213 in libjpeg-turbo, update to version 1.2.90-8.el7.
Where can I find more information about CVE-2018-11213?
You can find more information about CVE-2018-11213 in the following references: [link1](https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9a), [link2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1579976), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1579974).