Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5806

Опубликовано: 14 мар. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.

A NULL pointer dereference vulnerability in internal/dcraw_common.cpp:leaf_hdr_load_raw() function was found in LibRaw. A user can cause a denial of service when processing specially-crafted RAW data.

Отчет

This issue did not affect the versions of dcraw as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include the vulnerable code. This issue did not affect the versions of LibRaw as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dcrawNot affected
Red Hat Enterprise Linux 6dcrawNot affected
Red Hat Enterprise Linux 7dcrawWill not fix
Red Hat Enterprise Linux 7LibRawNot affected
Red Hat Enterprise Linux 8dcrawWill not fix
Red Hat Enterprise Linux 8LibRawNot affected
Red Hat Enterprise Linux 7libkdcrawFixedRHSA-2018:306530.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1591897LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp

EPSS

Процентиль: 66%
0.00511
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.

CVSS3: 6.5
nvd
почти 7 лет назад

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.

CVSS3: 6.5
debian
почти 7 лет назад

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_com ...

CVSS3: 6.5
github
больше 3 лет назад

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции leaf_hdr_load_raw() компонента internal/dcraw_common.cpp библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 66%
0.00511
Низкий

3.3 Low

CVSS3