#VU16692 Stack-based buffer overflow in LibRaw - CVE-2018-20337
Published: December 25, 2018
LibRaw
LibRaw LLC
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp. A remote attacker can trick the victim into opening a specially crafted input, trigger memory corruption and perform DoS attack.