Medium severity6.5OSV Advisory· Published May 6, 2018· Updated Jun 17, 2026
CVE-2018-10767
CVE-2018-10767
Description
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
70.1.0, 0.2.0, 0.2.1, …+ 1 more
- (no CPE)range: 0.1.0, 0.2.0, 0.2.1, …
- cpe:2.3:a:gnome:libgxps:*:*:*:*:*:*:*:*range: <=0.3.0
- cpe:2.3:a:redhat:ansible_tower:3.3:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- access.redhat.com/errata/RHBA-2019:0327nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:3140nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:3505nvdThird Party Advisory
News mentions
0No linked articles in our index yet.