VulnerabilityModified
CVE-2018-11212
The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
MEDIUM 6.5EPSS 5.01%
Does this matter?
Lower severity and a low EPSS score (5.01%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 5.01% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-369
- Affected
- ijg/libjpeg · debian/debian linux · canonical/ubuntu linux · netapp/oncommand unified manager · netapp/oncommand workflow automation · netapp/snapmanager · oracle/jdk · oracle/jre · redhat/satellite · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00028.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00013.html
- http://www.ijg.org/
- http://www.securityfocus.com/bid/106583Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0469Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0472Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0473Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0474Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0640Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1238
- https://access.redhat.com/errata/RHSA-2019:2052
- https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9aExploit, Third Party Advisory
- https://github.com/zzyyrr/divide-by-zero-in-libjpeg-9d.git
- https://lists.debian.org/debian-lts-announce/2019/01/msg00015.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190118-0001/Patch, Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03958en_us
- https://usn.ubuntu.com/3706-1/Third Party Advisory
- https://usn.ubuntu.com/3706-2/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00028.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00013.html
- http://www.ijg.org/
- http://www.securityfocus.com/bid/106583Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0469Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0472Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0473Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0474Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.