Vulnerability Name:

CVE-2018-10113 (CCN-141643)

Assigned:2018-04-14
Published:2018-04-14
Updated:2018-06-13
Summary:An issue was discovered in GEGL through 0.3.32. The process function in operations/external/ppm-load.c has unbounded memory allocation, leading to a denial of service (application crash) upon allocation failure.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-10113

Source: XF
Type: UNKNOWN
gegl-cve201810113-dos(141643)

Source: CCN
Type: GEGL GIT Repository
GEGL

Source: MISC
Type: Exploit, Vendor Advisory
https://github.com/xiaoqx/pocs/tree/master/gegl

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gegl:generic_graphics_library:*:*:*:*:*:*:*:* (Version <= 0.3.32)

  • Configuration CCN 1:
  • cpe:/a:gegl:gegl:0.3.32:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201810113
    V
    CVE-2018-10113
    2022-09-02
    oval:org.opensuse.security:def:26227
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:47214
    P
    bash-4.3-82.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47740
    P
    libmicrohttpd10-0.9.30-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47030
    P
    libidn-tools-1.28-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47632
    P
    gstreamer-1.8.3-9.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47475
    P
    ppp-2.4.7-3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47067
    P
    libpulse-mainloop-glib0-32bit-5.0-2.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47669
    P
    libSoundTouch0-1.7.1-5.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46939
    P
    file-5.19-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47601
    P
    ecryptfs-utils-103-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47512
    P
    sysvinit-tools-2.88+-99.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47391
    P
    libpcsclite1-1.8.10-6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48341
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46976
    P
    java-1_8_0-openjdk-1.8.0.101-14.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47638
    P
    guile-2.0.9-8.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47537
    P
    xorg-x11-server-7.6_1.18.3-71.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47428
    P
    libvmtools0-10.1.5-2.17 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47177
    P
    wireshark-1.12.13-31.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47703
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47574
    P
    clamav-0.100.2-33.18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46481
    P
    libgc1-7.2d-3.75 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48395
    P
    cups-pk-helper-0.2.5-3.72 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46652
    P
    evince-3.10.3-1.213 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46495
    P
    libmms0-0.6.2-15.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46518
    P
    libsoup-2_4-1-2.44.2-1.43 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48432
    P
    gnome-shell-3.20.4-70.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46532
    P
    logrotate-3.8.7-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46482
    P
    libgcrypt20-1.6.1-9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46807
    P
    pam-modules-12.1-23.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48378
    P
    bind-9.9.9P1-46.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46519
    P
    libspice-client-glib-2_0-8-0.25-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46844
    P
    socat-1.7.2.4-1.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46615
    P
    apache2-mod_jk-1.2.40-5.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26192
    P
    Security update for php72 (Important)
    2021-02-17
    oval:org.opensuse.security:def:24834
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:25104
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25533
    P
    Security update for ed (Low)
    2020-12-01
    oval:org.opensuse.security:def:24986
    P
    Security update for cronie (Low)
    2020-12-01
    oval:org.opensuse.security:def:18196
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25393
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:26229
    P
    Security update for xawtv (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18013
    P
    Security update for firebird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25206
    P
    Security update for tigervnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:25554
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18154
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18369
    P
    Security update for postgresql96 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18616
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18189
    P
    Security update for binutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18455
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:18547
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:19302
    P
    Security update for gegl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18366
    P
    Security update for libid3tag (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19127
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:25023
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:24860
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18162
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25243
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25591
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24787
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25123
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25510
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:18338
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:18604
    P
    Security update for libX11 and libxcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18132
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25409
    P
    Security update for apache-commons-httpclient (Important)
    2020-12-01
    oval:org.opensuse.security:def:18515
    P
    Security update for unixODBC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19276
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:18256
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:18489
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:24897
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:24797
    P
    Security update for kernel-firmware (Important)
    2020-12-01
    oval:org.opensuse.security:def:24824
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25160
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25547
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:25067
    P
    Security update for libjpeg-turbo (Important)
    2020-12-01
    oval:org.opensuse.security:def:25496
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:18281
    P
    Security update for php7 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25446
    P
    Security update for nfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26264
    P
    Security update for gegl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18047
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25356
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:18405
    P
    Security update for nasm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18638
    P
    Security update for libarchive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18005
    P
    Security update for tiff (Important)
    2020-12-01
    oval:org.opensuse.security:def:18220
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:18467
    P
    Security update for poppler (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18398
    P
    Security update for libquicktime (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19153
    P
    Security update for gegl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:126110
    P
    Security update for gegl (Moderate)
    2020-06-18
    oval:org.opensuse.security:def:127472
    P
    Security update for gegl (Moderate)
    2020-06-18
    oval:com.ubuntu.xenial:def:2018101130000000
    V
    CVE-2018-10113 on Ubuntu 16.04 LTS (xenial) - low.
    2018-04-16
    oval:com.ubuntu.artful:def:201810113000
    V
    CVE-2018-10113 on Ubuntu 17.10 (artful) - low.
    2018-04-16
    oval:com.ubuntu.xenial:def:201810113000
    V
    CVE-2018-10113 on Ubuntu 16.04 LTS (xenial) - low.
    2018-04-16
    oval:com.ubuntu.disco:def:2018101130000000
    V
    CVE-2018-10113 on Ubuntu 19.04 (disco) - low.
    2018-04-16
    oval:com.ubuntu.bionic:def:201810113000
    V
    CVE-2018-10113 on Ubuntu 18.04 LTS (bionic) - low.
    2018-04-16
    oval:com.ubuntu.cosmic:def:2018101130000000
    V
    CVE-2018-10113 on Ubuntu 18.10 (cosmic) - low.
    2018-04-16
    oval:com.ubuntu.cosmic:def:201810113000
    V
    CVE-2018-10113 on Ubuntu 18.10 (cosmic) - low.
    2018-04-16
    oval:com.ubuntu.bionic:def:2018101130000000
    V
    CVE-2018-10113 on Ubuntu 18.04 LTS (bionic) - low.
    2018-04-16
    oval:com.ubuntu.trusty:def:201810113000
    V
    CVE-2018-10113 on Ubuntu 14.04 LTS (trusty) - low.
    2018-04-16
    BACK
    gegl generic graphics library *
    gegl gegl 0.3.32