Note:
This project will be discontinued after December 13, 2021. [more]
2018-12-07
An integer overflow error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger a division by zero via specially crafted NOKIARAW file (Note: This vulnerability is caused due to an incomplete fix of CVE-2018-5804).
Products | Ubuntu_linux, Libraw |
Type | Integer Overflow or Wraparound (CWE-190) |
First patch |
https://github.com/LibRaw/LibRaw/commit/1d8d1b452e5dc74033ee9f846081a0efb616cc39 |
Relevant file/s |
• ./dcraw/dcraw.c (modified, +4, -1)
• ./internal/dcraw_common.cpp (modified, +4, -1) |
Links |
• https://github.com/LibRaw/LibRaw/blob/master/Changelog.txt
• https://usn.ubuntu.com/3838-1/ • https://secuniaresearch.flexerasoftware.com/secunia_research/2018-14/ • https://secuniaresearch.flexerasoftware.com/advisories/83507/ |
Navigation
Patch data:
Patched area:
(on by default)
Patched area: