Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19655

Опубликовано: 29 нояб. 2018
Источник: debian
EPSS Низкий

Описание

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ufrawfixed0.22-3.1package
dcrawfixed9.28-2package

Примечания

  • No security impact, crash in CLI tool

EPSS

Процентиль: 86%
0.02855
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

CVSS3: 3.3
redhat
около 8 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

CVSS3: 8.8
nvd
больше 7 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

CVSS3: 8.8
github
больше 4 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

suse-cvrf
больше 4 лет назад

Security update for dcraw

EPSS

Процентиль: 86%
0.02855
Низкий