CVE-2018-10126 PUBLISHED

ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.

EPSS 0.30% · 53.2th percentile

Risk Scores

EPSS Score
0.30%
53.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibjpeg6b0, 1:6b2-3
Ubuntu:18.04:LTSlibjpeg6b0, 1:6b2-3
Ubuntu:18.04:LTSlibjpeg90, 1:9b-2
Ubuntu:Pro:14.04:LTSlibjpeg6b6b1-4ubuntu1, 6b1-4ubuntu1+esm1, 0
Ubuntu:22.04:LTSlibjpeg91:9d-1, 0
Ubuntu:22.04:LTSlibjpeg-turbo2.0.6-0ubuntu2, 0, 2.1.1-0ubuntu1
Ubuntu:24.04:LTSlibjpeg91:9e-1, 0, 1:9e-1build1
Ubuntu:24.04:LTSlibjpeg6b0, 1:6b2-3.1
Ubuntu:25.10libjpeg91:9f-2, 0
Ubuntu:24.04:LTSlibjpeg-turbo0, 2.1.5-2ubuntu2, 2.1.5-2ubuntu1
Ubuntu:Pro:16.04:LTSlibjpeg-turbo1.4.2-0ubuntu2, 1.4.2-0ubuntu3, 1.4.2-0ubuntu3.1
Ubuntu:20.04:LTSlibjpeg91:9c-2, 0, 1:9d-1
Ubuntu:Pro:14.04:LTSlibjpeg-turbo1.3.0-0ubuntu2.1+esm2, 1.3.0-0ubuntu1, 1.3.0-0ubuntu2
Ubuntu:Pro:16.04:LTSlibjpeg91:9b-1, 0, 1:9a-2ubuntu1
Ubuntu:20.04:LTSlibjpeg-turbo2.0.3-0ubuntu1, 2.0.3-0ubuntu1.20.04.3, 0
Ubuntu:18.04:LTSlibjpeg-turbo1.5.2-0ubuntu5, 1.5.2-0ubuntu5.18.04.6, 1.5.2-0ubuntu5.18.04.4
Ubuntu:22.04:LTSlibjpeg6b0, 1:6b2-3
Ubuntu:25.10libjpeg6b0, 1:6b2-4
Ubuntu:25.10libjpeg-turbo2.1.5-3ubuntu2, 0, 2.1.5-4ubuntu2
Ubuntu:Pro:16.04:LTSlibjpeg6b0, 1:6b2-2, 1:6b2-2ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →