CVE-2018-3848: Fedoraproject Fedora
High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.
In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Affected products
- Fedoraproject Fedora: version 28 only
- Nasa Cfitsio: before 3.490 (fixed in 3.490)
Published 2018-04-16. Last modified 2026-06-17.