Lucene search

K
ubuntuUbuntuUSN-6377-1
HistorySep 18, 2023 - 12:00 a.m.

LibRaw vulnerability

2023-09-1800:00:00
ubuntu.com
26
libraw
vulnerability
ubuntu 20.04
remote attacker
denial of service
image decoder

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

24.0%

Releases

  • Ubuntu 20.04 LTS

Packages

  • libraw - raw image decoder library

Details

It was discovered that LibRaw incorrectly handled certain photo files. If a
user o automated system were tricked into processing a specially crafted
photo file, a remote attacker could possibly cause applications linked
against LibRaw to crash, resulting in a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchlibraw19< 0.19.5-1ubuntu1.3UNKNOWN
Ubuntu20.04noarchlibraw-bin< 0.19.5-1ubuntu1.3UNKNOWN
Ubuntu20.04noarchlibraw-bin-dbgsym< 0.19.5-1ubuntu1.3UNKNOWN
Ubuntu20.04noarchlibraw-dev< 0.19.5-1ubuntu1.3UNKNOWN
Ubuntu20.04noarchlibraw-doc< 0.19.5-1ubuntu1.3UNKNOWN
Ubuntu20.04noarchlibraw19-dbgsym< 0.19.5-1ubuntu1.3UNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

24.0%