CVE-2017-13735: Input Validation
Published Aug 29, 2017
·Updated
There is a floating point exception in the kodakradcloadraw function in dcrawcommon.cpp in LibRaw 0.18.2. It will lead to a remote denial of service attack.
Affected Software
1 affected component
Libraw Libraw=0.18.2
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13735?
CVE-2017-13735 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-13735?
To fix CVE-2017-13735, upgrade LibRaw to a version higher than 0.18.2.
3
What causes the vulnerability in CVE-2017-13735?
CVE-2017-13735 is caused by a floating point exception in the kodak_radc_load_raw function.
4
What types of attacks can exploit CVE-2017-13735?
CVE-2017-13735 can be exploited to perform remote denial of service attacks.
5
Which version of LibRaw is affected by CVE-2017-13735?
LibRaw version 0.18.2 is affected by CVE-2017-13735.