CVE-2018-5802
07.12.2018, 22:29
An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 𝑥 < 0.18.7 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||||||||||||||||||||||||||
| dcraw |
| ||||||||||||||||||||||||||||||||
| exactimage |
| ||||||||||||||||||||||||||||||||
| kodi |
| ||||||||||||||||||||||||||||||||
| libraw |
| ||||||||||||||||||||||||||||||||
| rawtherapee |
| ||||||||||||||||||||||||||||||||
| ufraw |
| ||||||||||||||||||||||||||||||||
| xbmc |
|
Common Weakness Enumeration
References