CVE-2025-43963
EUVD-2025-1196021.04.2025, 00:15
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 𝑥 < 0.21.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ufraw |
| ||||||||||||||||||
| darktable |
| ||||||||||||||||||
| exactimage |
| ||||||||||||||||||
| dcraw |
| ||||||||||||||||||
| rawtherapee |
| ||||||||||||||||||
| kodi |
| ||||||||||||||||||
| digikam |
| ||||||||||||||||||
| libraw |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libraw-devel |
| ||||||||||||||||
| libraw16 |
|
Amazon Linux Releases
Common Weakness Enumeration