Описание
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
Отчет
This issue did not affect the versions of LibRaw as shipped with Red Hat Enterprise Linux 7 as they did not include support for Fuji maker notes.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | LibRaw | Not affected | ||
Red Hat Enterprise Linux 8 | accountsservice | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | appstream-data | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | baobab | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | clutter | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | evince | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gdm | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gjs | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gnome-boxes | Fixed | RHSA-2020:1766 | 28.04.2020 |
Red Hat Enterprise Linux 8 | gnome-control-center | Fixed | RHSA-2020:1766 | 28.04.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
There is a stack-based buffer overflow in the parse_makernote function ...
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
Уязвимость функции parse_makernote библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.3 Low
CVSS3