CVE-2018-3849: Fedoraproject Fedora

High severity, CVSS 8.8. EPSS: 3.6% chance of exploitation in the next 30 days.

In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

Affected products

Published 2018-04-16. Last modified 2026-06-17.