CVE-2018-3846: Fedoraproject Fedora
High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Affected products
- Fedoraproject Fedora: version 28 only
- Nasa Cfitsio: version 3.42 only
Published 2018-04-16. Last modified 2026-06-17.