Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc2r-q5xw-m9fm

Опубликовано: 02 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

EPSS

Процентиль: 29%
0.00103
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

CVSS3: 5.5
redhat
почти 6 лет назад

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

CVSS3: 5.5
nvd
больше 3 лет назад

In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

CVSS3: 5.5
debian
больше 3 лет назад

In LibRaw, an out-of-bounds read vulnerability exists within the "simp ...

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость компонента x3f_utils_patched.cpp библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 29%
0.00103
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-125