Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5800

Опубликовано: 30 янв. 2018
Источник: redhat
CVSS3: 3.3

Описание

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

A heap-based out-of-bounds access flaw was found in the way LibRaw processed images. An attacker could potentially use this flaw to crash applications using LibRaw by tricking them into processing crafted images.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dcrawNot affected
Red Hat Enterprise Linux 6dcrawNot affected
Red Hat Enterprise Linux 7dcrawNot affected
Red Hat Enterprise Linux 7LibRawWill not fix
Red Hat Enterprise Linux 8dcrawNot affected
Red Hat Enterprise Linux 8LibRawNot affected
Red Hat Enterprise Linux 7libkdcrawFixedRHSA-2018:306530.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1553332LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

CVSS3: 6.5
nvd
почти 7 лет назад

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

CVSS3: 6.5
debian
почти 7 лет назад

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" functi ...

CVSS3: 6.5
github
больше 3 лет назад

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

CVSS3: 6.5
fstec
почти 8 лет назад

Уязвимость компонента internal/dcraw_common.cpp библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3