CVE-2018-19655

EUVD-2018-11339
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
dcraw_projectdcraw
𝑥
≤ 9.28
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dcraw
bookworm
9.28-3
fixed
bullseye
9.28-2
fixed
sid
9.28-7
fixed
trixie
9.28-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dcraw
bionic
needs-triage
cosmic
Fixed 9.28-2
released
disco
Fixed 9.28-2
released
eoan
Fixed 9.28-2
released
focal
Fixed 9.28-2
released
groovy
Fixed 9.28-2
released
hirsute
Fixed 9.28-2
released
impish
Fixed 9.28-2
released
jammy
Fixed 9.28-2
released
kinetic
Fixed 9.28-2
released
lunar
Fixed 9.28-2
released
mantic
Fixed 9.28-2
released
noble
Fixed 9.28-2
released
trusty
dne
xenial
needs-triage
ufraw
bionic
Fixed 0.22-3.1~build0.18.04.1
released
cosmic
Fixed 0.22-3.1~build0.18.14.1
released
disco
not-affected
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
needed