Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7996
HistoryDec 10, 2018 - 2:24 a.m.

Heap-Based Buffer Overflow

2018-12-1002:24:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.005

Percentile

76.3%

libraw.so is vulnerable to denial of service. The LibRaw::panasonic_load_raw() function in dcraw_common.cpp does not properly handle TIFF files, allowing an attacker to submit a malicious TIFF to cause a heap-based buffer overflow and crash the application.