CVE-2018-20544

unknown
Published — · Modified —
CVSS v3
—
CVSS v4 NEW
—
not yet in upstream
VIR risk
—

Description

There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2018-20544 NameCVE-2018-20544 DescriptionThere is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) ReferencesDLA-1631-1 Debian Bugs917807 Vulnerable and fixed packages The table below…

CVE-2018-20544

NameCVE-2018-20544
DescriptionThere is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1631-1
Debian Bugs917807

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libcaca (PTS)bullseye0.99.beta19-2.2fixed
bullseye (security)0.99.beta19-2.2+deb11u1fixed
bookworm0.99.beta20-3fixed
trixie0.99.beta20-5fixed
forky0.99.beta20-6fixed
sid0.99.beta20-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libcacasourcejessie0.99.beta19-2+deb8u1DLA-1631-1
libcacasourcestretch0.99.beta19-2.1~deb9u1
libcacasource(unstable)0.99.beta19-2.1low917807

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1652627
https://github.com/cacalabs/libcaca/issues/36
Upstream fix: https://github.com/cacalabs/libcaca/commit/84bd155087b93ab2d8d7cb5b1ac94ecd4cf4f93c

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://bugzilla.redhat.com/show_bug.cgi?id=1652627https://github.com/cacalabs/libcaca/issues/36Upstream fix: https://github.com/cacalabs/libcaca/commit/84bd155087b93ab2d8d7cb5b1ac94ecd4cf4f93c

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed0.99.beta19-2.1
debian debianbullseyefixed0.99.beta19-2.1
debian debianforkyfixed0.99.beta19-2.1
debian debiansidfixed0.99.beta19-2.1
debian debiantrixiefixed0.99.beta19-2.1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.