CVE-2018-14498

MEDIUM

libjpeg-turbo <1.5.90, MozJPEG <3.3.1 - DoS

Title source: llm
STIX 2.1

Description

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

References (11)

Core 11
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258
Exploit, Third Party Advisory x_refsource_misc
https://github.com/mozilla/mozjpeg/issues/299
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/03/msg00021.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2052
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3705
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4190-1/
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/07/msg00033.html

Scores

CVSS v3 6.5
EPSS 0.0030
EPSS Percentile 53.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (5)
debian/debian_linux 8.0
fedoraproject/fedora 28
libjpeg-turbo/libjpeg-turbo < 1.5.90
mozilla/mozjpeg < 3.3.1
opensuse/leap 15.0
Published Mar 07, 2019
Tracked Since Feb 18, 2026