CVE-2018-1152 describes a denial-of-service vulnerability in libjpeg-turbo versions 1.5.90 and earlier, affecting various distributions of Debian and Ubuntu Linux. This flaw allows an unauthenticated attacker to crash the application by providing a specially crafted BMP image, leading to a divide-by-zero error. With a CVSS score of 6.5 (Medium), this vulnerability is remotely exploitable with low attack complexity, requiring user interaction to process the malicious image, and primarily impacts availability. There is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.90CPE matchmatch criteria | cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:1.5.90:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] libturbo-jpeg Denial of Service
Jun 14, 2018[R1] libturbo-jpeg Denial of Service
Jun 14, 2018libturbo-jpeg Denial of Service
Jun 14, 2018libjpeg-turbo: Divide by zero allows for denial of service via crafted BMP image
Jun 13, 2018