Input validation error in LibRaw - CVE-2018-5819
Published: February 1, 2019
LibRaw
LibRaw LLC
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the parse_sinar_ia function
of dcraw_common.cpp due to insufficient validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted input and cause the service to crash.