CVE-2018-14498: Medium severity Libjpeg-turbo Libjpeg-turbo vulnerability
get8bitrow in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-14498?
CVE-2018-14498 is a vulnerability in libjpeg-turbo and MozJPEG that allows attackers to cause a denial of service via a crafted 8-bit BMP.
How does CVE-2018-14498 work?
CVE-2018-14498 works by exploiting a heap-based buffer over-read in the get_8bit_row function in rdbmp.c.
What is the severity of CVE-2018-14498?
CVE-2018-14498 has a severity rating of 6.5 (medium).
How can I fix CVE-2018-14498 in libjpeg-turbo?
To fix CVE-2018-14498 in libjpeg-turbo, you should update to version 1.5.90 or later.
How can I fix CVE-2018-14498 in MozJPEG?
To fix CVE-2018-14498 in MozJPEG, you should update to version 3.3.1 or later.