CVE-2018-18751: Double Free
An issue was discovered in GNU gettext 0.19.8. There is a double free in defaultaddmessage in read-catalog.c, related to an invalid free in pogramparse in po-gram-gen.y, as demonstrated by lt-msgfmt.
Other sources
GNU gettext is vulnerable to a denial of service, caused by a double free flaw in the defaultaddmessage function in read-catalog.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18751?
CVE-2018-18751 is classified as a moderate severity vulnerability due to its potential to cause a denial of service through a double free.
How do I fix CVE-2018-18751?
To fix CVE-2018-18751, update to the patched versions of the gettext package or any affected software distributions that address this vulnerability.
Which versions of gettext are affected by CVE-2018-18751?
CVE-2018-18751 affects gettext version 0.19.8 and earlier versions.
What are the potential impacts of CVE-2018-18751?
The potential impacts of CVE-2018-18751 include application crashes and denial of service due to memory corruption.
Is CVE-2018-18751 present in IBM Data Risk Manager software?
Yes, CVE-2018-18751 is present in IBM Data Risk Manager versions up to 2.0.6, which require an update for remediation.