ALT-PU-2017-1273-1
Closed vulnerabilities
Published: 2017-05-16
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-6886
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- DSA-3950
- DSA-3950
- 98605
- 98605
- https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251
- https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251
- https://secuniaresearch.flexerasoftware.com/advisories/75737/
- https://secuniaresearch.flexerasoftware.com/advisories/75737/
- https://secuniaresearch.flexerasoftware.com/secunia_research/2017-5/
- https://secuniaresearch.flexerasoftware.com/secunia_research/2017-5/
Published: 2017-05-16
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-6887
A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.
Severity: HIGH (7.8)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- DSA-3950
- DSA-3950
- 98592
- 98592
- https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251
- https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251
- https://secuniaresearch.flexerasoftware.com/advisories/75737/
- https://secuniaresearch.flexerasoftware.com/advisories/75737/
- https://secuniaresearch.flexerasoftware.com/secunia_research/2017-6/
- https://secuniaresearch.flexerasoftware.com/secunia_research/2017-6/