Input validation error in LibRaw - CVE-2018-5819

 

Input validation error in LibRaw - CVE-2018-5819

Published: February 1, 2019


Vulnerability identifier: #VU17353
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5819
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists in the parse_sinar_ia function
of dcraw_common.cpp due to insufficient validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted input and cause the service to crash.


Affected software

LibRaw
libraw (Ubuntu package)
libraw (Alpine package)
pidgin (Red Hat package)
glib2 (Red Hat package)
gnome-session (Red Hat package)
libkdcraw (Red Hat package)
accountsservice (Red Hat package)
plymouth (Red Hat package)
desktop-file-utils (Red Hat package)
cairo (Red Hat package)
pango (Red Hat package)
xchat (Red Hat package)
libgnomekbd (Red Hat package)
nautilus (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
mutter (Red Hat package)
gnome-shell (Red Hat package)
gnome-boxes (Red Hat package)
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Opensuse

How to mitigate CVE-2018-5819

Install updates from vendor's website.

libraw (Ubuntu package) - addressed in versions 0.17.1-1ubuntu0.5, 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1
pidgin (Red Hat package) - update to 2.10.11-8.el7
glib2 (Red Hat package) - update to 2.56.1-5.el7
gnome-session (Red Hat package) - update to 3.28.1-7.el7
libkdcraw (Red Hat package) - update to 4.10.5-7.el7
accountsservice (Red Hat package) - update to 0.6.50-5.el7
plymouth (Red Hat package) - update to 0.8.9-0.32.20140113.el7
desktop-file-utils (Red Hat package) - update to 0.23-2.el7
cairo (Red Hat package) - update to 1.15.12-4.el7
pango (Red Hat package) - update to 1.42.4-3.el7
xchat (Red Hat package) - update to 2.8.8-24.el7
libgnomekbd (Red Hat package) - update to 3.26.0-3.el7
nautilus (Red Hat package) - update to 3.26.3.1-6.el7
gnome-settings-daemon (Red Hat package) - update to 3.28.1-4.el7
gnome-shell-extensions (Red Hat package) - update to 3.28.1-7.el7
mutter (Red Hat package) - update to 3.28.3-10.el7
gnome-shell (Red Hat package) - update to 3.28.3-11.el7
gnome-boxes (Red Hat package) - update to 3.28.5-4.el7

External References

Related Security Bulletins