In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libraw | Feb 25, 2019 | Sep 20, 2017 | |
| Freebsd | freebsd-upgrade-package-libraw | Sep 28, 2017 | Sep 28, 2017 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 13, 2017 |
| Suse | — | suse-upgrade-libraw-develsuse-upgrade-libraw-devel-staticsuse-upgrade-libraw9 | Oct 25, 2017 | Sep 20, 2017 |
| Ubuntu | ubuntu-upgrade-libraw15ubuntu-upgrade-libraw16ubuntu-upgrade-libraw9 | Nov 23, 2017 | Sep 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub