6.8
CVSSv2

CVE-2017-18198

Published: 24/02/2018 Updated: 31/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

print_iso9660_recurse in iso-info.c in GNU libcdio prior to 1.0.0 allows remote malicious users to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu libcdio

Vendor Advisories

Synopsis Low: libcdio security update Type/Severity Security Advisory: Low Topic An update for libcdio is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...
Several security issues were fixed in libcdio ...
A heap corruption bug was found in the way libcdio handled processing of ISO files An attacker could potentially use this flaw to crash applications using libcdio by tricking them into processing crafted ISO files, thus resulting in local DoS(CVE-2017-18198) A double-free flaw was found in the way libcdio handled processing of ISO files An attac ...
A heap corruption bug was found in the way libcdio handled processing of ISO files An attacker could potentially use this flaw to crash applications using libcdio by tricking them into processing crafted ISO files, thus resulting in local DoS ...
print_iso9660_recurse in iso-infoc in GNU libcdio before 100 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file ...