Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5804

Опубликовано: 14 мар. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.

Отчет

This issue did not affect the versions of LibRaw as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code. This issue did not affect the versions of dcraw as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include the vulnerable code. This issue did not affect the versions of libkdcraw as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dcrawNot affected
Red Hat Enterprise Linux 6dcrawNot affected
Red Hat Enterprise Linux 7dcrawNot affected
Red Hat Enterprise Linux 7libkdcrawNot affected
Red Hat Enterprise Linux 7LibRawNot affected
Red Hat Enterprise Linux 8dcrawNot affected
Red Hat Enterprise Linux 8LibRawNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=1591879LibRaw: type confusion error in identify() function in internal/dcraw_common.cpp

EPSS

Процентиль: 54%
0.00314
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.

CVSS3: 6.5
nvd
около 7 лет назад

A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.

CVSS3: 6.5
debian
около 7 лет назад

A type confusion error within the "identify()" function (internal/dcra ...

CVSS3: 6.5
github
больше 3 лет назад

A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.

CVSS3: 6.5
fstec
почти 8 лет назад

Уязвимость компонента internal/dcraw_common.cpp библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 54%
0.00314
Низкий

3.3 Low

CVSS3