VYPR

rpm package

suse/libraw&distro=SUSE Linux Enterprise Software Development Kit 12 SP3

pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3

Vulnerabilities (24)

  • CVE-2017-6886CriMay 16, 2017
    affected < 0.15.4-9.2fixed 0.15.4-9.2

    An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.

  • CVE-2017-6890CriMay 15, 2017
    affected < 0.15.4-9.2fixed 0.15.4-9.2

    A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer overflow.

  • CVE-2017-6889CriMay 15, 2017
    affected < 0.15.4-9.2fixed 0.15.4-9.2

    An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.

  • CVE-2015-3885May 19, 2015
    affected < 0.15.4-9.2fixed 0.15.4-9.2

    Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

Page 2 of 2