High severity7.1NVD Advisory· Published Nov 26, 2018· Updated Jun 17, 2026
CVE-2018-19565
CVE-2018-19565
Description
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
Affected products
5cpe:2.3:a:dcraw_project:dcraw:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dcraw_project:dcraw:*:*:*:*:*:*:*:*range: <=9.28
- (no CPE)range: <=9.28
- osv-coords3 versionspkg:rpm/opensuse/dcraw&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/dcraw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/dcraw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 9.28.0-150000.3.3.1+ 2 more
- (no CPE)range: < 9.28.0-150000.3.3.1
- (no CPE)range: < 9.28.0-3.3.1
- (no CPE)range: < 9.28.0-3.3.1
Patches
Vulnerability mechanics
References
2- seclists.org/oss-sec/2018/q4/165nvdMailing ListThird Party Advisory
- seclists.org/oss-sec/2018/q4/171nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.