Lucene search

K
rosalinuxROSA LABROSA-SA-2024-2350
HistoryFeb 20, 2024 - 9:19 a.m.

Advisory ROSA-SA-2024-2350

2024-02-2009:19:52
ROSA LAB
abf.rosalinux.ru
9
libraw
vulnerability
buffer boundaries
sensitive data
integrity
denial of service
yum update
rosa-server79

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.5%

Software: LibRaw 0.19.4
OS: rosa-server79

package_evr_string: LibRaw-0.19.4-2.res7

CVE-ID: CVE-2021-32142
BDU-ID: 2023-03833
CVE-Crit: HIGH
CVE-DESC.: A vulnerability in the LibRaw_buffer_datastream::gets function of the src/libraw_datastream.cpp component of the LibRaw image processing library is related to writes beyond buffer boundaries. Exploitation of the vulnerability allows an attacker to gain access to sensitive data, compromise its integrity, and cause a denial of service via a specially crafted file
CVE-STATUS: Fixed
CVE-REV: Execute yum update grub2 to close.

OSVersionArchitecturePackageVersionFilename
rosaanynoarchlibraw< 0.19.4UNKNOWN

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.5%