Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5805

Опубликовано: 14 мар. 2018
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.

LibRaw is vulnerable to stack-based buffer overflow in internal/dcraw_common.cpp:quicktake_100_load_raw() function when processing specially-crafted RAW data. An attacker could potentially use this flaw to cause an arbitrary code execution or denial of service.

Отчет

This issue did not affect the versions of dcraw as shipped with Red Hat Enterprise Linux 5 as they did not include the vulnerable code. This issue affects the versions of dcraw as shipped with Red Hat Enterprise Linux 6. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dcrawNot affected
Red Hat Enterprise Linux 6dcrawWill not fix
Red Hat Enterprise Linux 7dcrawWill not fix
Red Hat Enterprise Linux 7LibRawWill not fix
Red Hat Enterprise Linux 8dcrawWill not fix
Red Hat Enterprise Linux 8LibRawNot affected
Red Hat Enterprise Linux 7libkdcrawFixedRHSA-2018:306530.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1591887LibRaw: Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp

EPSS

Процентиль: 65%
0.00492
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.

CVSS3: 8.8
nvd
почти 7 лет назад

A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.

CVSS3: 8.8
debian
почти 7 лет назад

A boundary error within the "quicktake_100_load_raw()" function (inter ...

CVSS3: 8.8
github
больше 3 лет назад

A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость компонента internal/dcraw_common.cpp библиотеки для обработки изображений LibRaw, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 65%
0.00492
Низкий

7 High

CVSS3