An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libraw | Jan 31, 2022 | Dec 7, 2018 | |
| Freebsd | freebsd-upgrade-package-libraw | Feb 16, 2018 | Feb 15, 2018 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Dec 7, 2018 |
| Suse | — | suse-upgrade-libraw-develsuse-upgrade-libraw-devel-staticsuse-upgrade-libraw9 | Dec 21, 2017 | Dec 21, 2017 |
| Ubuntu | ubuntu-upgrade-libraw15ubuntu-upgrade-libraw16ubuntu-upgrade-libraw9 | Apr 25, 2018 | Dec 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub