In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libraw | Feb 25, 2019 | Sep 20, 2017 |
| Freebsd | — | Upgrade libraw | Sep 28, 2017 | Sep 28, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 13, 2017 |
| Suse | — | Upgrade libraw9Upgrade libraw-devel-staticUpgrade libraw-devel | Oct 25, 2017 | Sep 20, 2017 |
| Ubuntu | — | Upgrade libraw9Upgrade libraw16Upgrade libraw15 | Nov 23, 2017 | Sep 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub