Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25274
HistoryMay 10, 2020 - 11:23 p.m.

Arbitrary Code Execution

2020-05-1023:23:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

EPSS

0.01

Percentile

83.3%

libraw is vulnerable to arbitrary code execution. The vulnerability exists as an array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.