CVE-2018-3846: Fedoraproject Fedora

High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.

In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

Affected products

Published 2018-04-16. Last modified 2026-06-17.