rpm package
suse/libraw&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP6
pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-43964 | Low | 2.9 | < 0.21.1-150600.3.5.1 | 0.21.1-150600.3.5.1 | Apr 21, 2025 | In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values. | |
| CVE-2025-43963 | Low | 2.9 | < 0.21.1-150600.3.5.1 | 0.21.1-150600.3.5.1 | Apr 21, 2025 | In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing. | |
| CVE-2025-43962 | Low | 2.9 | < 0.21.1-150600.3.5.1 | 0.21.1-150600.3.5.1 | Apr 21, 2025 | In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations. | |
| CVE-2025-43961 | Low | 2.9 | < 0.21.1-150600.3.5.1 | 0.21.1-150600.3.5.1 | Apr 21, 2025 | In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser. |
- affected < 0.21.1-150600.3.5.1fixed 0.21.1-150600.3.5.1
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
- affected < 0.21.1-150600.3.5.1fixed 0.21.1-150600.3.5.1
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.
- affected < 0.21.1-150600.3.5.1fixed 0.21.1-150600.3.5.1
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
- affected < 0.21.1-150600.3.5.1fixed 0.21.1-150600.3.5.1
In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.