CVE-2018-14498

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
07/03/2019
Last modified:
17/06/2026

Description

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:*:*:*:*:*:*:*:* 1.5.90 (including)
cpe:2.3:a:mozilla:mozjpeg:*:*:*:*:*:*:*:* 3.3.1 (including)
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools