CVE-2018-7998 describes a NULL function pointer dereference vulnerability in libvips versions prior to 8.6.3, specifically within the vips_region_generate function in region.c. This flaw, stemming from a race condition during a failed delayed load, affects Debian Linux and libvips itself. The vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a high-severity issue. It can be triggered remotely with user interaction (e.g., opening a crafted image file) and could lead to a denial of service or potentially other unspecified impacts, including high confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or active threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.3CPE matchmatch criteria | cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.