Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-14498
Description:get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap- based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Test IDs: 1.3.6.1.4.1.25623.1.0.891719   1.3.6.1.4.1.25623.1.1.10.2019.0132   1.3.6.1.4.1.25623.1.1.2.2019.1892   1.3.6.1.4.1.25623.1.1.2.2019.1955   1.3.6.1.4.1.25623.1.0.892302  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-14498
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7YP4QUEYGHI4Q7GIAVFVKWQ7DJMBYLU/
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55
https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258
https://github.com/mozilla/mozjpeg/issues/299
https://lists.debian.org/debian-lts-announce/2019/03/msg00021.html
https://lists.debian.org/debian-lts-announce/2020/07/msg00033.html
RedHat Security Advisories: RHSA-2019:2052
https://access.redhat.com/errata/RHSA-2019:2052
RedHat Security Advisories: RHSA-2019:3705
https://access.redhat.com/errata/RHSA-2019:3705
SuSE Security Announcement: openSUSE-SU-2019:1118 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html
SuSE Security Announcement: openSUSE-SU-2019:1343 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html
https://usn.ubuntu.com/4190-1/




© 1998-2025 E-Soft Inc. All rights reserved.