First published: Wed Sep 20 2017(Updated: )
In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LibRaw | <=0.18.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14608 is classified as a medium severity vulnerability due to its potential to disclose sensitive information or cause application crashes.
To fix CVE-2017-14608, upgrade LibRaw to a version greater than 0.18.4, as this flaw has been addressed in subsequent releases.
Users of LibRaw versions up to and including 0.18.4 are affected by CVE-2017-14608.
An attacker could exploit CVE-2017-14608 to read out of bounds memory, potentially disclosing sensitive data or causing application instability.
CVE-2017-14608 is reported to occur in the kodak_65000_load_raw function in the dcraw/dcraw.c and internal/dcraw_common.cpp files.