Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26140
HistoryAug 06, 2020 - 9:33 p.m.

Denial Of Service (DoS)

2020-08-0621:33:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.008

Percentile

81.9%

libraw is vulnerable to denial of service (DoS). The vulnerability exists due to lacks of a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.

References