Stack-based buffer overflow in LibRaw - CVE-2018-5805

 

Stack-based buffer overflow in LibRaw - CVE-2018-5805

Published: December 10, 2018 / Updated: January 3, 2019


Vulnerability identifier: #VU16342
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5805
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists due to stack-based buffer overflow within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp). A local attacker can submit specially crafted images, trigger memory corruption and cause the service to crash.

Affected software

LibRaw
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power
Opensuse

How to mitigate CVE-2018-5805

Update to version 0.18.8.

LibRaw - update to 0.18.8

External References

Related Security Bulletins