CVE-2017-6887: Buffer Overflow
Published May 16, 2017
·Updated
A boundary error within the "parsetiffifd()" function (internal/dcrawcommon.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.
Affected Software
1 affected component
Libraw Libraw<=0.18.1
Remediation
Event History
May 16, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6887?
CVE-2017-6887 is classified as a medium severity vulnerability due to the potential for memory corruption.
2
How do I fix CVE-2017-6887?
To fix CVE-2017-6887, update LibRaw to version 0.18.2 or later.
3
What software versions are affected by CVE-2017-6887?
CVE-2017-6887 affects LibRaw versions prior to 0.18.2.
4
What type of exploitation is possible with CVE-2017-6887?
CVE-2017-6887 can be exploited by using a specially crafted KDC file to cause memory corruption.
5
Which function contains the vulnerability in CVE-2017-6887?
The vulnerability in CVE-2017-6887 exists in the "parse_tiff_ifd()" function in the internal/dcraw_common.cpp file.