PT-2015-7774 · Libraw+2 · Libraw+2

Alphafuzzer

·

Published

2015-12-02

·

Updated

2024-06-15

·

CVE-2015-8366

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibRaw versions prior to 0.17.1
Description The issue is related to an array index error in the smal decode segment function, which can be exploited by context-dependent attackers to cause memory errors and potentially execute arbitrary code. This is achieved through vectors related to indexes.
Recommendations For versions prior to 0.17.1, update to version 0.17.1 or later to resolve the issue.

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2049
CVE-2015-8366
MGASA-2015-0469
OPENSUSE-SU-2024:11480-1
USN-3492-1

Affected Products

Alt Linux
Libraw
Ubuntu