CVE-2017-6886: Buffer Overflow
Published May 16, 2017
·Updated
An error within the "parsetiffifd()" function (internal/dcrawcommon.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
Affected Software
1 affected component
Libraw Libraw<=0.18.1
Remediation
Event History
May 16, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6886?
CVE-2017-6886 is classified as a high severity vulnerability due to the potential for memory corruption.
2
How do I fix CVE-2017-6886?
To fix CVE-2017-6886, upgrade LibRaw to version 0.18.2 or later.
3
What software is affected by CVE-2017-6886?
LibRaw versions up to and including 0.18.1 are affected by CVE-2017-6886.
4
Can CVE-2017-6886 be exploited remotely?
CVE-2017-6886 can potentially be exploited remotely when processing specially crafted TIFF files.
5
What is the nature of the vulnerability described in CVE-2017-6886?
CVE-2017-6886 is a vulnerability that involves an error in the parse_tiff_ifd() function, leading to memory corruption.