VDB
CVE-2018-25154
CVE-2018-25154
PUBLISHED
CVSS 9.800000190734863 CRITICAL
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.
EPSS 0.38% · 31.1th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.38%
31.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:24.04:LTS | barcode | 0.99-6, 0, 0.99-7 |
| Ubuntu:25.10 | barcode | 0.99-9, 0 |
| Ubuntu:22.04:LTS | barcode | 0, 0.99-5, 0.99-4 |
| Ubuntu:16.04:LTS | barcode | 0.98+debian-9.1, 0 |
| Ubuntu:20.04:LTS | barcode | 0, 0.99-3 |
| Ubuntu:18.04:LTS | barcode | 0, *, * |
Timeline
- Dec 24, 2025 CVE Published
- Dec 24, 2025 PoC Published
- Dec 24, 2025 PoC Published
- Dec 25, 2025 EPSS Score
- Dec 29, 2025 EPSS Score
- Jan 2, 2026 EPSS Score
- Jan 6, 2026 EPSS Score
- Jan 10, 2026 EPSS Score
- Jan 14, 2026 EPSS Score
- Jan 18, 2026 EPSS Score
- Jan 22, 2026 EPSS Score
- Jan 26, 2026 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-25154 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-25154 third-party-advisory
- https://lists.gnu.org/archive/html/bug-barcode/2018-05/msg00002.html third-party-advisory
- https://www.exploit-db.com/exploits/44797 third-party-advisory
- https://directory.fsf.org/wiki/Barcode third-party-advisory
- https://www.gnu.org/software/barcode/ third-party-advisory