CVE-2015-8367: Critical severity libraw vulnerability
Published Jan 14, 2020
·Updated
The phaseonecorrect function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.
Affected Software
1 affected component
Libraw Libraw<0.17.1
Event History
Jan 14, 2020
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
Description
Frequently Asked Questions
1
What is CVE-2015-8367?
CVE-2015-8367 is a vulnerability in Libraw before version 0.17.1 that allows attackers to cause memory errors and possibly execute arbitrary code.
2
What is the severity level of CVE-2015-8367?
CVE-2015-8367 has a severity level of critical with a severity value of 9.8.
3
How can this vulnerability impact my system?
This vulnerability can lead to memory errors and potentially enable attackers to execute arbitrary code on your system.
4
Which software versions are affected by CVE-2015-8367?
Libraw versions before 0.17.1 are affected by this vulnerability.
5
Is there a fix available for CVE-2015-8367?
Yes, updating to Libraw version 0.17.1 or later mitigates this vulnerability.