LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libraw | Feb 15, 2019 | Dec 22, 2018 |
| Debian | — | Upgrade libraw | Jan 31, 2022 | Dec 22, 2018 |
| Huawei Euleros 2_0_sp8 | — | — | Aug 31, 2020 | Dec 22, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 22, 2018 |
| Suse | — | Upgrade libraw-toolsUpgrade libraw16Upgrade libraw9Upgrade libraw-develUpgrade libraw-devel-static | Jan 19, 2019 | Dec 22, 2018 |
| Ubuntu | — | Upgrade libraw15Upgrade libraw16 | May 22, 2019 | Dec 22, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub