PT-2017-4293 · Libraw+3 · Libraw+3

Twi1Ight

·

Published

2017-09-13

·

Updated

2024-11-08

·

CVE-2017-14608

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions: LibRaw versions prior to 0.18.5
Description: The issue is related to an out of bounds read flaw in the kodak 65000 load raw function, affecting components dcraw/dcraw.c and internal/dcraw common.cpp. This could potentially allow an attacker to disclose sensitive memory or cause an application crash. The vulnerability can be exploited by a remote attacker to gain access to confidential data and cause a denial of service.
Recommendations: For LibRaw versions prior to 0.18.5, update to version 0.18.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the kodak 65000 load raw function in dcraw/dcraw.c and internal/dcraw common.cpp until a patch is available.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2341
BDU:2023-07748
CVE-2017-14608
DLA-1109-1
DLA-2903-1
MGASA-2020-0157
OESA-2024-2363
OESA-2024-2364
OESA-2024-2365
OESA-2024-2366
OPENSUSE-SU-2022_1277-1
OPENSUSE-SU-2024:10712-1
SUSE-SU-2017:3392-1
SUSE-SU-2022:1277-1
SUSE-SU-2022:1749-1
USN-3492-1

Affected Products

Alt Linux
Libraw
Suse
Ubuntu