CVE-2017-14608: Critical severity libraw vulnerability
In LibRaw through 0.18.4, an out of bounds read flaw related to kodak65000loadraw has been reported in dcraw/dcraw.c and internal/dcrawcommon.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14608?
CVE-2017-14608 is classified as a medium severity vulnerability due to its potential to disclose sensitive information or cause application crashes.
How do I fix CVE-2017-14608?
To fix CVE-2017-14608, upgrade LibRaw to a version greater than 0.18.4, as this flaw has been addressed in subsequent releases.
Who is affected by CVE-2017-14608?
Users of LibRaw versions up to and including 0.18.4 are affected by CVE-2017-14608.
What types of attacks can be carried out using CVE-2017-14608?
An attacker could exploit CVE-2017-14608 to read out of bounds memory, potentially disclosing sensitive data or causing application instability.
Where in LibRaw does CVE-2017-14608 occur?
CVE-2017-14608 is reported to occur in the kodak_65000_load_raw function in the dcraw/dcraw.c and internal/dcraw_common.cpp files.