CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
86.2%
There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of service attack. (CVE-2017-13735) A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack. (CVE-2017-14265) LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file. (CVE-2017-14348)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Mageia | 5 | noarch | libraw | < 0.16.2-1.4 | libraw-0.16.2-1.4.mga5 |
Mageia | 6 | noarch | libraw | < 0.18.5-1 | libraw-0.18.5-1.mga6 |
bugs.mageia.org/show_bug.cgi?id=21716
lists.fedoraproject.org/archives/list/[email protected]/thread/4OTWHVODHFROYHMCNRUAZHNZDBH7YSPO/
lists.fedoraproject.org/archives/list/[email protected]/thread/CMHXYQOFX5OQSBWNNMCVGJLYXTZHXYTM/
lists.fedoraproject.org/archives/list/[email protected]/thread/OPKCTEX7MK4ILYKIBQBK3VBM5U5CRJKK/
lists.fedoraproject.org/archives/list/[email protected]/thread/TVI7PQ5NTNFOL4EQTLNZOPGCDLKJKXST/
lists.opensuse.org/opensuse-updates/2017-09/msg00099.html
www.libraw.org/news/libraw-0-18-4
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
86.2%