PT-2017-4214 · Libraw+2 · Libraw+2

Published

2017-11-21

·

Updated

2022-01-29

·

CVE-2017-16910

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibRaw versions prior to 0.18.6
Description The issue is related to a buffer data boundary read in the internal/dcraw common.cpp component of the LibRaw image processing library. It allows a remote attacker to cause a Denial of Service condition by exploiting an error within the LibRaw::xtrans interpolate() function.
Recommendations For versions prior to 0.18.6, update to version 0.18.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the LibRaw::xtrans interpolate() function until a patch is available.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2757
BDU:2022-05947
CVE-2017-16910
DLA-2903-1
MGASA-2017-0468
USN-3615-1

Affected Products

Alt Linux
Libraw
Ubuntu