4.3
CVSSv2

CVE-2018-11212

Published: 16/05/2018 Updated: 20/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote malicious users to cause a denial of service (divide-by-zero error) via a crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ijg libjpeg 9a

debian debian linux 8.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 12.04

netapp snapmanager

netapp oncommand workflow automation

netapp oncommand unified manager

oracle jdk 1.8.0

oracle jdk 1.7.0

oracle jre 8.0

oracle jdk 11.0.1

redhat satellite 5.8

redhat enterprise linux desktop 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 6.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 6.0

redhat enterprise linux server 7.0

opensuse leap 15.0

Vendor Advisories

Debian Bug report logs - #904719 libjpeg9: CVE-2018-11813 Package: src:libjpeg9; Maintainer for src:libjpeg9 is Bill Allombert <ballombe@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 23 Jun 2018 07:15:02 UTC Severity: normal Tags: security Found in version libjpeg9/1:9b-2 Reply or sub ...
Debian Bug report logs - #902176 libjpeg9: CVE-2018-11212 CVE-2018-11213 CVE-2018-11214 Package: src:libjpeg9; Maintainer for src:libjpeg9 is Bill Allombert <ballombe@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 23 Jun 2018 07:15:02 UTC Severity: normal Tags: security Found in version lib ...
Several security issues were fixed in Libjpeg6b ...
libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file ...
libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file ...
Synopsis Critical: java-180-ibm security update Type/Severity Security Advisory: Critical Topic An update for java-180-ibm is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring ...
Synopsis Critical: java-180-ibm security update Type/Severity Security Advisory: Critical Topic An update for java-180-ibm is now available for Red Hat Enterprise Linux 7 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring ...
Synopsis Critical: java-171-ibm security update Type/Severity Security Advisory: Critical Topic An update for java-171-ibm is now available for Red Hat Enterprise Linux 7 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring ...
Synopsis Critical: java-171-ibm security update Type/Severity Security Advisory: Critical Topic An update for java-171-ibm is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring ...
Synopsis Moderate: java-180-ibm security update Type/Severity Security Advisory: Moderate Topic An update for java-180-ibm is now available for Red Hat Satellite 58Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Critical: java-180-ibm security update Type/Severity Security Advisory: Critical Topic An update for java-180-ibm is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) ...
Synopsis Moderate: libjpeg-turbo security update Type/Severity Security Advisory: Moderate Topic An update for libjpeg-turbo is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ba ...
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file(CVE-2016-3616) libjpeg 9c has a large loop because read_pixel in rdtargac mishandles EOF(CVE-2018-11813) An out-of-bounds read vulnerability has been discovered in libjpeg ...
A divide by zero vulnerability has been discovered in libjpeg-turbo in alloc_sarray function of jmemmgrc file An attacker could use this vulnerability to cause a denial of service via a crafted file ...
A divide by zero vulnerability has been discovered in libjpeg-turbo in alloc_sarray function of jmemmgrc file An attacker could use this vulnerability to cause a denial of service via a crafted file(CVE-2018-11212) ...
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file(CVE-2016-3616) A divide by zero vulnerability has been discovered in libjpeg-turbo in alloc_sarray function of jmemmgrc file An attacker could use this vulnerability to ca ...
Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java contain the following vulnerabilities: CVE-2018-11212, CVE-2019-2422, CVE-2019-2426 Affected products and versions are listed below Please upgrade your version to the appropriate version These vulnerabilities exist in Cosminexus Developer's Kit for Java(TM) and Hita ...
Multiple vulnerabilities have been found in Hitachi Command Suite and Hitachi Infrastructure Analytics Advisor CVE-2018-11212, CVE-2019-2422, CVE-2019-2426 Affected products and versions are listed below Please upgrade your version to the appropriate version, or apply the Workarounds ...