ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
Security update for libraw
This update for libraw fixes the following issues:
Security issues fixed:
- CVE-2018-20337: Fixed a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp (bsc#1120519)
- CVE-2018-20365: Fixed a heap-based buffer overflow in the raw2image function of libraw_cxx.cpp (bsc#1120500)
- CVE-2018-20364: Fixed a NULL pointer dereference in the copy_bayer function of libraw_cxx.cpp (bsc#1120499)
- CVE-2018-20363: Fixed a NULL pointer dereference in the raw2image function of libraw_cxx.cpp (bsc#1120498)
- CVE-2018-5817: Fixed an infinite loop in the unpacked_load_raw function of dcraw_common.cpp (bsc#1120515)
- CVE-2018-5818: Fixed an infinite loop in the parse_rollei function of dcraw_common.cpp (bsc#1120516)
- CVE-2018-5819: Fixed a denial of service in the parse_sinar_ia function of dcraw_common.cpp (bsc#1120517)
This update was imported from the SUSE:SLE-15:Update update project.
Π‘ΠΏΠΈΡΠΎΠΊ ΠΏΠ°ΠΊΠ΅ΡΠΎΠ²
openSUSE Leap 15.0
Π‘ΡΡΠ»ΠΊΠΈ
- E-Mail link for openSUSE-SU-2019:0094-1
- SUSE Security Ratings
- SUSE Bug 1120498
- SUSE Bug 1120499
- SUSE Bug 1120500
- SUSE Bug 1120515
- SUSE Bug 1120516
- SUSE Bug 1120517
- SUSE Bug 1120519
- SUSE CVE CVE-2018-20337 page
- SUSE CVE CVE-2018-20363 page
- SUSE CVE CVE-2018-20364 page
- SUSE CVE CVE-2018-20365 page
- SUSE CVE CVE-2018-5817 page
- SUSE CVE CVE-2018-5818 page
- SUSE CVE CVE-2018-5819 page
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-20337
- SUSE Bug 1120519
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-20363
- SUSE Bug 1120498
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-20364
- SUSE Bug 1120499
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-20365
- SUSE Bug 1120498
- SUSE Bug 1120499
- SUSE Bug 1120500
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-5817
- SUSE Bug 1120515
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-5818
- SUSE Bug 1120516
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.
ΠΠ°ΡΡΠΎΠ½ΡΡΡΠ΅ ΠΏΡΠΎΠ΄ΡΠΊΡΡ
Π‘ΡΡΠ»ΠΊΠΈ
- CVE-2018-5819
- SUSE Bug 1120517