CVE-2018-7998

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-7998
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7998.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-7998
Related
Published
2018-03-09T19:29:01Z
Modified
2025-01-15T01:36:02.200231Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vipsregiongenerate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.

References

Affected packages

Debian:11 / vips

Package

Name
vips
Purl
pkg:deb/debian/vips?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.4.5-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / vips

Package

Name
vips
Purl
pkg:deb/debian/vips?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.4.5-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / vips

Package

Name
vips
Purl
pkg:deb/debian/vips?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.4.5-2

Ecosystem specific

{
    "urgency": "low"
}

Git / github.com/jcupitt/libvips

Affected ranges

Type
GIT
Repo
https://github.com/jcupitt/libvips
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Type
GIT
Repo
https://github.com/libvips/libvips
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v7.*

v7.28.0
v7.30.0

v8.*

v8.0-beta
v8.1
v8.2.2
v8.2.3
v8.3.0
v8.4.2
v8.5.1
v8.5.2
v8.5.3
v8.5.4
v8.5.5
v8.5.6
v8.5.7
v8.5.8
v8.5.9
v8.6.0
v8.6.0-alpha1
v8.6.0-alpha2
v8.6.0-alpha3
v8.6.0-alpha4
v8.6.0-alpha5
v8.6.0-beta1
v8.6.0-beta2
v8.6.1
v8.6.2