PT-2019-4978 · Libraw+3 · Libraw+3
Published
2018-11-23
·
Updated
2022-01-29
·
CVE-2018-5818
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
LibRaw versions prior to 0.19.1
Description
The issue is related to the
parse rollei() function in the LibRaw library, which can lead to uncontrolled resource consumption. This can be exploited by a remote attacker to cause a denial of service. The error within the function can trigger an infinite loop.Recommendations
For versions prior to 0.19.1, update to version 0.19.1 or later to resolve the issue.
As a temporary workaround, consider disabling the
parse rollei() function until a patch is available.Fix
Resource Exhaustion
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Libraw
Suse
Ubuntu