Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7096
HistoryJul 18, 2018 - 8:13 a.m.

Denial Of Service (DoS)

2018-07-1808:13:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.008

Percentile

81.7%

libraw.so is vulnerable to denial of service (DoS) attacks. The library contains an off-by-one error in the LibRaw::kodak_ycbcr_load_raw() function of dcraw_common.cpp, allowing a malicious user to pass an image file to the application to cause a heap-based buffer overflow, crashing the application.