Lucene search

K
rosalinuxROSA LABROSA-SA-2021-1821
HistoryJul 02, 2021 - 4:37 p.m.

Advisory ROSA-SA-2021-1821

2021-07-0216:37:23
ROSA LAB
abf.rosalinux.ru
12
dcraw 9.19
cobalt 7.9
buffer re-reading
excessive heap buffer reads
floating point exception
application crash
security advisory
unix

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

29.4%

Software: dcraw 9.19
OS: Cobalt 7.9

CVE-ID: CVE-2018-19565
CVE-Crit: HIGH
CVE-DESC: Buffer re-reading in crop_masked_pixels in dcraw before 9.28 could have been used by attackers who could provide malicious files to crash the application that binds the dcraw code or leak private information.
CVE-STATUS: default
CVE-REV: default

CVE-ID: CVE-2018-19566
CVE-Crit: HIGH
CVE-DESC: Excessive heap buffer reads in parse_tiff_ifd in dcraw before 9.28 could have been exploited by attackers capable of providing malicious files to crash the application that binds the dcraw code or leak private information.
CVE-STATUS: default
CVE-REV: default

CVE-ID: CVE-2018-19567
CVE-Crit: MEDIUM
CVE-DESC: The floating point exception in parse_tiff_ifd in dcraw before 9.28 could have been exploited by attackers capable of providing malicious files to crash an application that binds dcraw code.
CVE-STATUS: default
CVE-REV: default

CVE-ID: CVE-2018-19568
CVE-Crit: MEDIUM
CVE-DESC: The floating point exception in kodak_radc_load_raw in dcraw before 9.28 could have been used by attackers who could provide malicious files to crash an application that binds dcraw code.
CVE-STATUS: default
CVE-REV: default

OSVersionArchitecturePackageVersionFilename
Cobaltanynoarchdcraw< 9.19UNKNOWN

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

29.4%