Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14265

Опубликовано: 08 сент. 2017
Источник: redhat
CVSS3: 3.3

Описание

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

A stack buffer overflow flaw was found in the way dcraw handled processing of RAW image files. This flaw could potentially be used to crash the dcraw process by supplying it a specially crafted image file .

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dcrawNot affected
Red Hat Enterprise Linux 6dcrawNot affected
Red Hat Enterprise Linux 7dcrawWill not fix
Red Hat Enterprise Linux 7libkdcrawNot affected
Red Hat Enterprise Linux 7LibRawWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1494405libraw: Stack based buffer overflow in the xtrans_interpolate function

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

CVSS3: 9.8
nvd
больше 8 лет назад

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

CVSS3: 9.8
debian
больше 8 лет назад

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in ...

CVSS3: 9.8
github
больше 3 лет назад

A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость функции xtrans_interpolate компонента internal/dcraw_common.cpp библиотеки для обработки изображений LibRaw, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

3.3 Low

CVSS3