SB2019031115 - Division by zero in openjdk8 (Alpine package)
Published: March 11, 2019
Security Bulletin ID
SB2019031115
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Division by zero (CVE-ID: CVE-2018-11212)
The vulnerability allows a remote attacker to cause DoS condition.The weakness exists due to division by zero error within the libjpeg library within the libjpeg-turbo in alloc_sarray() function of jmemmgr.c file. A remote attacker can pass a specially crafted file the to affected application and cause application to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=6324621827b1c65e3f404065482b4e3e55001f2b
- https://git.alpinelinux.org/aports/commit/?id=7338b4c596715b5d463d170a9ab7696820f62677
- https://git.alpinelinux.org/aports/commit/?id=84a0eb0c2983c847c94bb11f506d5f3eec1f3941
- https://git.alpinelinux.org/aports/commit/?id=f790fa8355877352cc7484e2a784a4f76e6c5324
- https://git.alpinelinux.org/aports/commit/?id=fdf726d41a1108ea5d2673bc9c635ac16ad1d6b9
- https://git.alpinelinux.org/aports/commit/?id=15b4e95534e731b4068f051a7796f4d104255493