PT-2015-7775 · Libraw+3 · Libraw+3

Alphafuzzer

·

Publicado

2015-12-02

·

Atualizado

2025-04-28

·

CVE-2015-8367

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libraw versions prior to 0.17.1
Description The issue is related to memory object initialization in the phase one correct function, which can cause memory errors and potentially allow attackers to execute arbitrary code.
Recommendations For versions prior to 0.17.1, update to version 0.17.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the phase one correct function until a patch is available.

Correção

Improper Initialization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2049
CVE-2015-8367
MGASA-2015-0469
OPENSUSE-SU-2024:10156-1
SUSE-SU-2017:2300-1
SUSE-SU-2025:1380-1
USN-3492-1

Produtos afetados

Alt Linux
Libraw
Suse
Ubuntu