Vulnerabilities > CVE-2018-11416 - Double Free vulnerability in Jpegoptim Project Jpegoptim 1.4.5

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
jpegoptim-project
CWE-415

Summary

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

Vulnerable Configurations

Part Description Count
Application
Jpegoptim_Project
1

Common Weakness Enumeration (CWE)