Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-19655

Опубликовано: 29 нояб. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 8.8

Описание

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

released

9.28-2
devel

released

9.28-2
disco

released

9.28-2
eoan

released

9.28-2
esm-apps/bionic

needs-triage

esm-apps/focal

released

9.28-2
esm-apps/jammy

released

9.28-2
esm-apps/noble

released

9.28-2
esm-apps/xenial

needs-triage

Показывать по

РелизСтатусПримечание
bionic

released

0.22-3.1~build0.18.04.1
cosmic

released

0.22-3.1~build0.18.14.1
devel

DNE

disco

not-affected

0.22-3.1
eoan

DNE

esm-apps/bionic

released

0.22-3.1~build0.18.04.1
esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

focal

DNE

Показывать по

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 3.3
redhat
больше 7 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

CVSS3: 8.8
nvd
около 7 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

CVSS3: 8.8
debian
около 7 лет назад

A stack-based buffer overflow in the find_green() function of dcraw th ...

CVSS3: 8.8
github
больше 3 лет назад

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

suse-cvrf
больше 3 лет назад

Security update for dcraw

6.8 Medium

CVSS2

8.8 High

CVSS3