Critical severity9.8NVD Advisory· Published Oct 29, 2018· Updated Jun 17, 2026
CVE-2018-18751
CVE-2018-18751
Description
An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
25cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- osv-coords17 versionspkg:rpm/almalinux/gettextpkg:rpm/almalinux/gettext-common-develpkg:rpm/almalinux/gettext-develpkg:rpm/almalinux/gettext-libspkg:rpm/opensuse/gettext-csharp&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/gettext-csharp&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/gettext-java&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/gettext-java&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/gettext-runtime&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/gettext-runtime&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/gettext-runtime-mini&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/gettext-runtime-mini&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/gettext-csharp&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/gettext-runtime&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/gettext-runtime&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/gettext-runtime&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/gettext-runtime&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
< 0.19.8.1-17.el8+ 16 more
- (no CPE)range: < 0.19.8.1-17.el8
- (no CPE)range: < 0.19.8.1-17.el8
- (no CPE)range: < 0.19.8.1-17.el8
- (no CPE)range: < 0.19.8.1-17.el8
- (no CPE)range: < 0.19.8.1-lp151.5.3.1
- (no CPE)range: < 0.19.8.1-lp152.6.3.1
- (no CPE)range: < 0.19.8.1-lp151.5.3.1
- (no CPE)range: < 0.19.8.1-lp152.6.3.1
- (no CPE)range: < 0.19.8.1-lp151.5.3.1
- (no CPE)range: < 0.19.8.1-lp152.6.3.1
- (no CPE)range: < 0.19.8.1-lp151.5.3.1
- (no CPE)range: < 0.19.8.1-lp152.6.3.1
- (no CPE)range: < 0.19.8.1-bp151.2.1
- (no CPE)range: < 0.19.8.1-4.8.1
- (no CPE)range: < 0.19.8.1-4.8.1
- (no CPE)range: < 0.19.2-3.3.6
- (no CPE)range: < 0.19.2-3.3.6
Patches
Vulnerability mechanics
References
8- github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/doublefreenvdExploitThird Party Advisory
- github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/heapcorruptionnvdExploitThird Party Advisory
- usn.ubuntu.com/3815-1/nvdThird Party Advisory
- usn.ubuntu.com/3815-2/nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-08/msg00061.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-08/msg00065.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-09/msg00025.htmlnvd
- access.redhat.com/errata/RHSA-2019:3643nvd
News mentions
0No linked articles in our index yet.