CVE Vulnerabilities

CVE-2018-11813

Excessive Iteration

Published: Jun 06, 2018 | Modified: Jun 25, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW

libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

Weakness

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

Affected Software

Name Vendor Start Version End Version
Libjpeg Ijg 9c (including) 9c (including)
Libjpeg-turbo Ubuntu bionic *
Libjpeg-turbo Ubuntu esm-infra/xenial *
Libjpeg-turbo Ubuntu precise/esm *
Libjpeg-turbo Ubuntu trusty *
Libjpeg-turbo Ubuntu trusty/esm *
Libjpeg-turbo Ubuntu upstream *
Libjpeg-turbo Ubuntu xenial *
Libjpeg6b Ubuntu bionic *
Libjpeg6b Ubuntu devel *
Libjpeg6b Ubuntu eoan *
Libjpeg6b Ubuntu esm-apps/bionic *
Libjpeg6b Ubuntu esm-apps/focal *
Libjpeg6b Ubuntu esm-apps/jammy *
Libjpeg6b Ubuntu esm-apps/noble *
Libjpeg6b Ubuntu esm-apps/xenial *
Libjpeg6b Ubuntu focal *
Libjpeg6b Ubuntu groovy *
Libjpeg6b Ubuntu hirsute *
Libjpeg6b Ubuntu impish *
Libjpeg6b Ubuntu jammy *
Libjpeg6b Ubuntu kinetic *
Libjpeg6b Ubuntu lunar *
Libjpeg6b Ubuntu mantic *
Libjpeg6b Ubuntu noble *
Libjpeg6b Ubuntu trusty *
Libjpeg6b Ubuntu trusty/esm *
Libjpeg6b Ubuntu upstream *
Libjpeg6b Ubuntu xenial *
Libjpeg9 Ubuntu artful *
Libjpeg9 Ubuntu bionic *
Libjpeg9 Ubuntu cosmic *
Libjpeg9 Ubuntu disco *
Libjpeg9 Ubuntu eoan *
Libjpeg9 Ubuntu esm-apps/bionic *
Libjpeg9 Ubuntu esm-apps/xenial *
Libjpeg9 Ubuntu upstream *
Libjpeg9 Ubuntu xenial *
Red Hat Enterprise Linux 7 RedHat libjpeg-turbo-0:1.2.90-8.el7 *

References