suse · CVE-2018-25014

Quick triage

Priority: critical Published: 2021-05-30 14:20:09 UTC Updated: 2025-11-05 03:17:50 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-25014 severity critical: SUSE including 242 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 293 product×package rows across 20 product lines (SUSE CaaS Platform 4.5, SUSE Enterprise Storage 7, … (20 product lines)): Known Affected 231, Known Not Affected 55, Fixed 7.

Description:

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

cvelogic Threat Intelligence