An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libraw | Sep 20, 2017 | May 16, 2017 |
| Debian | — | Upgrade libraw | Aug 22, 2017 | May 16, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 11, 2017 |
| Suse | — | Upgrade libraw16Upgrade libraw-develUpgrade libraw-devel-staticUpgrade libraw9 | May 31, 2017 | May 16, 2017 |
| Ubuntu | — | Upgrade libraw9Upgrade libraw15Upgrade libraw16 | Nov 23, 2017 | May 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub