A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libraw | Sep 20, 2017 | May 16, 2017 |
| Debian | — | Upgrade libraw | Aug 22, 2017 | May 16, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 11, 2017 |
| Suse | — | Upgrade libraw-devel-staticUpgrade libraw16Upgrade libraw-develUpgrade libraw9 | May 31, 2017 | May 16, 2017 |
| Ubuntu | — | Upgrade libraw9Upgrade libraw16Upgrade libraw15 | Nov 23, 2017 | May 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub