Description
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-13361 | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size. |
References
| Link | Providers |
|---|---|
| https://github.com/dropbox/lepton/issues/112 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:12:27.304Z
Reserved: 2019-04-23T00:00:00.000Z
Link: CVE-2018-20819
No data.
Status : Modified
Published: 2019-04-23T14:29:00.320
Modified: 2024-11-21T04:02:15.173
Link: CVE-2018-20819
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD