First published: Tue May 16 2017(Updated: )
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
LibRaw | <=0.18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6886 is classified as a high severity vulnerability due to the potential for memory corruption.
To fix CVE-2017-6886, upgrade LibRaw to version 0.18.2 or later.
LibRaw versions up to and including 0.18.1 are affected by CVE-2017-6886.
CVE-2017-6886 can potentially be exploited remotely when processing specially crafted TIFF files.
CVE-2017-6886 is a vulnerability that involves an error in the parse_tiff_ifd() function, leading to memory corruption.