6.5
CVSSv3

CVE-2018-1152

Published: 18/06/2018 Updated: 31/07/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.

Vulnerable Product Search on Vulmon Subscribe to Product

libjpeg-turbo libjpeg-turbo 1.5.90

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 17.10

canonical ubuntu linux 12.04

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #902950 libjpeg-turbo: CVE-2018-1152 Package: src:libjpeg-turbo; Maintainer for src:libjpeg-turbo is Ondřej Surý <ondrej@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 3 Jul 2018 19:24:01 UTC Severity: important Tags: patch, security, upstream Found in versi ...
libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file ...
libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file ...
libjpeg-turbo 1590 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image ...