There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of service attack.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libraw | Oct 3, 2022 | Aug 29, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 29, 2017 |
| Debian | — | Upgrade libraw | Jan 31, 2022 | Aug 29, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 22, 2017 |
| Suse | — | Upgrade libraw-develUpgrade libraw-devel-staticUpgrade libraw9Upgrade libraw16 | Oct 3, 2017 | Aug 29, 2017 |
| Ubuntu | — | Upgrade libraw16Upgrade libraw15Upgrade libraw9 | Nov 23, 2017 | Aug 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub