Описание
A flaw was found in LibRaw, an open-source library for processing raw image files. This vulnerability is a buffer overflow, which occurs in the stretch() and fuji_rotate() functions. A buffer overflow can allow an attacker to overwrite memory, potentially leading to a denial of service or the execution of unauthorized code.
Отчет
This Important flaw in LibRaw, a library for processing raw image files, is a buffer overflow in the stretch() and fuji_rotate() functions. Successful exploitation requires a local attacker to trick a user into processing a specially crafted raw image file, which could lead to arbitrary code execution or a denial of service. Red Hat Enterprise Linux 9 is affected, while Red Hat Enterprise Linux 8 and older versions are not vulnerable as they ship with older, unaffected versions of LibRaw or do not contain the vulnerable code.
Меры по смягчению последствий
Mitigation for this issue involves avoiding the processing of untrusted raw image files. As this vulnerability resides within a library, there are no direct configuration or operational controls to disable the vulnerable functions without impacting applications that rely on LibRaw for image processing.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libraw1394 | Not affected | ||
| Red Hat Enterprise Linux 7 | LibRaw | Not affected | ||
| Red Hat Enterprise Linux 7 | libraw1394 | Not affected | ||
| Red Hat Enterprise Linux 8 | LibRaw | Not affected | ||
| Red Hat Enterprise Linux 8 | libraw1394 | Not affected | ||
| Red Hat Enterprise Linux 9 | LibRaw | Affected |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).
7.3 High
CVSS3