CVE-2018-3849

Publication date

2018-04-16 15:00:00

Family

talos

State

PUBLISHED

Description

In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.