CVE-2018-11813
CVE-2018-11813 is a high-severity vulnerability in Ijg Libjpeg with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-834.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 3% (87th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-834
- Affected product: Ijg Libjpeg
- Published:
- Last modified:
Description
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
Frequently asked questions
- What is CVE-2018-11813?
- libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
- How severe is CVE-2018-11813?
- CVE-2018-11813 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2018-11813 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (87th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-11813?
- CVE-2018-11813 affects Ijg Libjpeg. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-11813?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2018-11813 published?
- CVE-2018-11813 was published on 2018-06-06 and last updated on 2026-06-17.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html
- http://www.ijg.org/files/jpegsrc.v9d.tar.gz
- https://access.redhat.com/errata/RHSA-2019:2052
- https://bugs.gentoo.org/727908
- https://github.com/ChijinZ/security_advisories/blob/master/libjpeg-v9c/mail.pdf
- https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9c
Affected products (1)
- cpe:2.3:a:ijg:libjpeg:9c:*:*:*:*:*:*:*
More vulnerabilities in Ijg Libjpeg
- CVE-2020-14153 — High (CVSS 7.1): In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table…
- CVE-2020-14152 — High (CVSS 7.1): In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use…
- CVE-2018-11214 — Medium (CVSS 6.5): An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a…
- CVE-2018-11213 — Medium (CVSS 6.5): An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a…
- CVE-2018-11212 — Medium (CVSS 6.5): An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a…
All CVEs affecting Ijg Libjpeg →
Other CWE-834 (Excessive Iteration) vulnerabilities
- CVE-2017-12587 — High (CVSS 8.8): ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
- CVE-2026-59644 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
- CVE-2024-42071 — High (CVSS 7.8): In the Linux kernel, the following vulnerability has been resolved: ionic: use dev_consume_skb_any outside of napi If…
- CVE-2026-64641 — High (CVSS 7.5): Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0…
- CVE-2025-62707 — High (CVSS 7.5): pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this…
- CVE-2025-56571 — High (CVSS 7.5): Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper…