Unrated severityOSV Advisory· Published Dec 21, 2018· Updated Aug 5, 2024
CVE-2018-20337
CVE-2018-20337
Description
There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
Affected products
19- osv-coords18 versionspkg:rpm/almalinux/accountsservice-develpkg:rpm/almalinux/baobabpkg:rpm/almalinux/clutterpkg:rpm/almalinux/clutter-develpkg:rpm/almalinux/clutter-docpkg:rpm/almalinux/gjs-develpkg:rpm/almalinux/gnome-menuspkg:rpm/almalinux/gnome-menus-develpkg:rpm/almalinux/gnome-tweakspkg:rpm/almalinux/mozjs52pkg:rpm/almalinux/mozjs52-develpkg:rpm/almalinux/mozjs60pkg:rpm/almalinux/mozjs60-develpkg:rpm/almalinux/valapkg:rpm/almalinux/vala-develpkg:rpm/opensuse/libraw&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/libraw&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015
< 0.6.50-8.el8+ 17 more
- (no CPE)range: < 0.6.50-8.el8
- (no CPE)range: < 3.28.0-4.el8
- (no CPE)range: < 1.26.2-8.el8
- (no CPE)range: < 1.26.2-8.el8
- (no CPE)range: < 1.26.2-8.el8
- (no CPE)range: < 1.56.2-4.el8
- (no CPE)range: < 3.13.3-11.el8
- (no CPE)range: < 3.13.3-11.el8
- (no CPE)range: < 3.28.1-7.el8
- (no CPE)range: < 52.9.0-2.el8.alma
- (no CPE)range: < 52.9.0-2.el8.alma
- (no CPE)range: < 60.9.0-4.el8.alma
- (no CPE)range: < 60.9.0-4.el8
- (no CPE)range: < 0.40.19-1.el8
- (no CPE)range: < 0.40.19-1.el8
- (no CPE)range: < 0.18.9-lp150.2.6.1
- (no CPE)range: < 0.20.2-4.1
- (no CPE)range: < 0.18.9-3.8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- usn.ubuntu.com/3989-1/mitrevendor-advisoryx_refsource_UBUNTU
- github.com/LibRaw/LibRaw/issues/192mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.