An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libraw | Jan 31, 2022 | Dec 7, 2018 |
| Freebsd | — | Upgrade libraw | Feb 16, 2018 | Feb 15, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 7, 2018 |
| Suse | — | Upgrade libraw-develUpgrade libraw-devel-staticUpgrade libraw9 | Dec 21, 2017 | Dec 21, 2017 |
| Ubuntu | — | Upgrade libraw9Upgrade libraw16Upgrade libraw15 | Apr 25, 2018 | Dec 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub