Infinite loop in LibRaw - CVE-2018-5813
Published: December 10, 2018
LibRaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to due to improper parsing of files by the parse_minolta() function, as defined in the dcraw.c source code file of the affected software. A remote attacker can send trick the victim into accessing a file that submits malicious input, trigger an infinite loop condition that causes the affected software to crash or become unresponsive.