PT-2017-4293 · Libraw+3 · Libraw+3

Twi1Ight

·

Publicado

2017-09-13

·

Atualizado

2024-11-08

·

CVE-2017-14608

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions: LibRaw versions prior to 0.18.5
Description: The issue is related to an out of bounds read flaw in the kodak 65000 load raw function, affecting components dcraw/dcraw.c and internal/dcraw common.cpp. This could potentially allow an attacker to disclose sensitive memory or cause an application crash. The vulnerability can be exploited by a remote attacker to gain access to confidential data and cause a denial of service.
Recommendations: For LibRaw versions prior to 0.18.5, update to version 0.18.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the kodak 65000 load raw function in dcraw/dcraw.c and internal/dcraw common.cpp until a patch is available.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2341
BDU:2023-07748
CVE-2017-14608
DLA-1109-1
DLA-2903-1
MGASA-2020-0157
OESA-2024-2363
OESA-2024-2364
OESA-2024-2365
OESA-2024-2366
OPENSUSE-SU-2022_1277-1
OPENSUSE-SU-2024:10712-1
SUSE-SU-2017:3392-1
SUSE-SU-2022:1277-1
SUSE-SU-2022:1749-1
USN-3492-1

Produtos afetados

Alt Linux
Libraw
Suse
Ubuntu