PT-2018-2803 · Libraw+7 · Libraw+7

Dawnyang-Cn

·

Publicado

2018-12-18

·

Atualizado

2024-06-15

·

CVE-2018-20337

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LibRaw version 0.19.1
Description The issue is related to a stack-based buffer overflow in the parse makernote function of dcraw common.cpp in LibRaw. This can be exploited by a remote attacker to cause a denial of service or potentially other unspecified impacts. The vulnerability is associated with a buffer overflow in memory.
Recommendations For LibRaw version 0.19.1, consider disabling the parse makernote function as a temporary workaround until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2020:1766
ALT-PU-2018-2957
BDU:2019-02106
CESA-2020_1766
CVE-2018-20337
OPENSUSE-SU-2019:0094-1
OPENSUSE-SU-2019_0094-1
OPENSUSE-SU-2024:10980-1
RHSA-2020:1766
RHSA-2020_1766
RLSA-2020:1766
SUSE-SU-2019:0133-1
SUSE-SU-2019_0133-1
USN-3989-1

Produtos afetados

Alt Linux
Almalinux
Centos
Libraw
Red Hat
Rocky Linux
Suse
Ubuntu