Bug ID 1094621
Summary VUL-1: CVE-2018-11416: jpegoptim: invalid use of realloc()and free(), which allows remote attackers to cause a denial of service
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.0
Hardware Other
URL https://smash.suse.de/issue/206440/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee lazy.kent@opensuse.org
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
CC avvissu@yandex.by
Found By Security Response Team
Blocker ---

CVE-2018-11416

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc()
and free(), which allows remote attackers to cause a denial of service
(application crash) or possibly have unspecified other impact.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11416
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11416.html
https://github.com/tjko/jpegoptim/issues/57
https://github.com/tjko/jpegoptim/blob/master/README


You are receiving this mail because: