Stack-based buffer overflow in LibRaw - CVE-2018-20337

 

Stack-based buffer overflow in LibRaw - CVE-2018-20337

Published: December 25, 2018


Vulnerability identifier: #VU16692
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20337
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp. A remote attacker can trick the victim into opening a specially crafted input, trigger memory corruption and perform DoS attack.


Affected software

LibRaw
gnome-remote-desktop (Red Hat package)
accountsservice (Red Hat package)
libvncserver (Red Hat package)
libraw (Ubuntu package)
gjs (Red Hat package)
gtk3 (Red Hat package)
gnome-tweaks (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
gdm (Red Hat package)
evince (Red Hat package)
gnome-boxes (Red Hat package)
gnome-software (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
appstream-data (Red Hat package)
mozjs60 (Red Hat package)
LibRaw
LibRaw (Red Hat package)
vala (Red Hat package)
libxslt (Red Hat package)
clutter (Red Hat package)
gnome-menus (Red Hat package)
vinagre (Red Hat package)
gnome-session (Red Hat package)
gnome-online-accounts (Red Hat package)
gnome-terminal (Red Hat package)
mozjs52 (Red Hat package)
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora

How to mitigate CVE-2018-20337

Install updates from vendor's website.

gnome-remote-desktop (Red Hat package) - update to 0.1.6-8.el8
accountsservice (Red Hat package) - update to 0.6.50-8.el8
libvncserver (Red Hat package) - update to 0.9.11-14.el8
libraw (Ubuntu package) - addressed in versions 0.17.1-1ubuntu0.5, 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1
gjs (Red Hat package) - update to 1.56.2-4.el8
gtk3 (Red Hat package) - update to 3.22.30-5.el8
gnome-tweaks (Red Hat package) - update to 3.28.1-7.el8
nautilus (Red Hat package) - update to 3.28.1-12.el8
gnome-control-center (Red Hat package) - update to 3.28.2-19.el8
gdm (Red Hat package) - update to 3.28.3-29.el8
evince (Red Hat package) - update to 3.28.4-4.el8
gnome-boxes (Red Hat package) - update to 3.28.5-8.el8
gnome-software (Red Hat package) - update to 3.30.6-3.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-4.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-9.el8
gnome-shell (Red Hat package) - update to 3.32.2-14.el8
mutter (Red Hat package) - update to 3.32.2-34.el8
appstream-data (Red Hat package) - update to 8-20191129.el8
mozjs60 (Red Hat package) - update to 60.9.0-4.el8
LibRaw - update to 0.19.2-1.fc29
LibRaw (Red Hat package) - update to 0.19.5-1.el8
vala (Red Hat package) - update to 0.40.19-1.el8
libxslt (Red Hat package) - update to 1.1.32-4.el8
clutter (Red Hat package) - update to 1.26.2-8.el8
gnome-menus (Red Hat package) - update to 3.13.3-11.el8
vinagre (Red Hat package) - update to 3.22.0-21.el8
gnome-session (Red Hat package) - update to 3.28.1-8.el8
gnome-online-accounts (Red Hat package) - update to 3.28.2-1.el8
gnome-terminal (Red Hat package) - update to 3.28.3-1.el8
mozjs52 (Red Hat package) - update to 52.9.0-2.el8

External References

Related Security Bulletins