CVE-2017-18198: GNU Libcdio

High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.

print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.

Affected products

  • GNU Libcdio: before 1.0.0 (fixed in 1.0.0)

Published 2018-02-24. Last modified 2026-06-17.