High severity7.1NVD Advisory· Published Nov 26, 2018· Updated Jun 17, 2026
CVE-2018-19566
CVE-2018-19566
Description
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
Affected products
6cpe:2.3:a:dcraw_project:dcraw:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dcraw_project:dcraw:*:*:*:*:*:*:*:*range: <=9.28
- (no CPE)range: <=9.28
- osv-coords4 versionspkg:rpm/opensuse/dcraw&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/dcraw&distro=openSUSE%20Tumbleweedpkg:rpm/suse/dcraw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/dcraw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 9.28.0-150000.3.3.1+ 3 more
- (no CPE)range: < 9.28.0-150000.3.3.1
- (no CPE)range: < 9.28.0-2.1
- (no CPE)range: < 9.28.0-3.3.1
- (no CPE)range: < 9.28.0-3.3.1
Patches
Vulnerability mechanics
References
2- seclists.org/oss-sec/2018/q4/165nvdMailing ListThird Party Advisory
- seclists.org/oss-sec/2018/q4/171nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.