Red Hat Bugzilla – Bug 1561206
CVE-2018-8975 netpbm: heap-buffer-overflow in pm_mallocarray2 function in lib/util/mallocvar.c
Last modified: 2018-06-15 12:17:14 EDT
A flaw was found in Netpbm through 10.81.03. The pm_mallocarray2 function in lib/util/mallocvar.c allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask. References: https://github.com/xiaoqx/pocs/tree/master/netpbm
Created netpbm tracking bugs for this issue: Affects: fedora-all [bug 1561207]