A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libraw | Sep 20, 2017 | May 16, 2017 | |
| Debian | debian-upgrade-libraw | Aug 22, 2017 | May 16, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | May 11, 2017 | |
| Suse | — | suse-upgrade-libraw-develsuse-upgrade-libraw-devel-staticsuse-upgrade-libraw16suse-upgrade-libraw9 | May 31, 2017 | May 16, 2017 |
| Ubuntu | ubuntu-upgrade-libraw15ubuntu-upgrade-libraw16ubuntu-upgrade-libraw9 | Nov 23, 2017 | May 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub