Improper Initialization in LibRaw - CVE-2015-8367

 

Improper Initialization in LibRaw - CVE-2015-8367

Published: January 14, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30445
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8367
CWE-ID: CWE-665
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.


Affected software

LibRaw
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
libraw (Alpine package)
jasper (Alpine package)
libraw-devel-static
libraw-devel
LibRaw

How to mitigate CVE-2015-8367

Install update from vendor's website.

LibRaw - update to 0.17.1
libraw (Alpine package) - update to 0.17.1-r0
libraw-devel-static - update to 0.15.4-45.1
libraw-devel - update to 0.15.4-45.1
LibRaw - addressed in versions 0.16.2-3.el6, 0.16.2-3.fc21, 0.16.2-3.fc22, 0.16.2-3.fc23

External References

Related Security Bulletins