Improper Initialization in LibRaw - CVE-2015-8367
Published: January 14, 2020 / Updated: July 17, 2020
Vulnerability identifier: #VU30445
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8367
CWE-ID: CWE-665
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.
Affected software
LibRaw
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
libraw (Alpine package)
jasper (Alpine package)
libraw-devel-static
libraw-devel
LibRaw
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
libraw (Alpine package)
jasper (Alpine package)
libraw-devel-static
libraw-devel
LibRaw
How to mitigate CVE-2015-8367
Install update from vendor's website.
LibRaw - update to 0.17.1
libraw (Alpine package) - update to 0.17.1-r0
libraw-devel-static - update to 0.15.4-45.1
libraw-devel - update to 0.15.4-45.1
LibRaw - addressed in versions 0.16.2-3.el6, 0.16.2-3.fc21, 0.16.2-3.fc22, 0.16.2-3.fc23
libraw (Alpine package) - update to 0.17.1-r0
libraw-devel-static - update to 0.15.4-45.1
libraw-devel - update to 0.15.4-45.1
LibRaw - addressed in versions 0.16.2-3.el6, 0.16.2-3.fc21, 0.16.2-3.fc22, 0.16.2-3.fc23
External References
Related Security Bulletins
- Multiple vulnerabilities in LibRaw
- Improper Initialization in jasper (Alpine package)
- Improper Initialization in libraw (Alpine package)
- Gentoo update for LibRaw
- Fedora 23 update for LibRaw
- Fedora EPEL 6 update for LibRaw
- Fedora 22 update for LibRaw
- Fedora 21 update for LibRaw
- SUSE update for libraw