First published: Tue Jan 14 2020(Updated: )
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw Libraw | <0.17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8367 is a vulnerability in Libraw before version 0.17.1 that allows attackers to cause memory errors and possibly execute arbitrary code.
CVE-2015-8367 has a severity level of critical with a severity value of 9.8.
This vulnerability can lead to memory errors and potentially enable attackers to execute arbitrary code on your system.
Libraw versions before 0.17.1 are affected by this vulnerability.
Yes, updating to Libraw version 0.17.1 or later mitigates this vulnerability.