Vulnerabilities > CVE-2018-7589 - Double Free vulnerability in Cimg .220

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
cimg
CWE-415
nessus

Summary

An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.

Vulnerable Configurations

Part Description Count
Application
Cimg
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-1735CBC422.NASL
    descriptionUpdate to 2.3.6 release Fixes CVE-2018-7587, CVE-2018-7588, CVE-2018-7589, CVE-2018-7637, CVE-2018-7638, CVE-2018-7639, CVE-2018-7640, CVE-2018-7641 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2019-01-03
    plugin id120252
    published2019-01-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/120252
    titleFedora 28 : 1:CImg (2018-1735cbc422)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-1934.NASL
    descriptionSeveral issues have been found in cimg, a powerful image processing library. CVE-2019-1010174 is related to a missing string sanitization on URLs, which might result in a command injection when loading a special crafted image. The other CVEs are about heap-based buffer over-reads or double frees when loading an image. For Debian 8
    last seen2020-06-01
    modified2020-06-02
    plugin id129408
    published2019-09-30
    reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/129408
    titleDebian DLA-1934-1 : cimg security update
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-4C9E9B82D1.NASL
    descriptionUpdate to 2.3.6 release. Fixes CVE-2018-7587, CVE-2018-7588, CVE-2018-7589, CVE-2018-7637, CVE-2018-7638, CVE-2018-7639, CVE-2018-7640, CVE-2018-7641 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2019-01-03
    plugin id120403
    published2019-01-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/120403
    titleFedora 29 : 1:CImg (2018-4c9e9b82d1)