CVE-2017-6890: Buffer Overflow
Published May 15, 2017
·Updated
A boundary error within the "foveonloadcamf()" function (dcrawfoveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer overflow.
Affected Software
1 affected component
Libraw LibRaw-demosaic-pack-GPL2<=0.18.1
Remediation
Event History
May 15, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6890?
CVE-2017-6890 has a high severity level due to its potential for causing a stack-based buffer overflow.
2
How do I fix CVE-2017-6890?
The recommended fix for CVE-2017-6890 is to upgrade to LibRaw-demosaic-pack-GPL2 version 0.18.2 or later.
3
What software is affected by CVE-2017-6890?
CVE-2017-6890 affects LibRaw-demosaic-pack-GPL2 versions prior to 0.18.2.
4
What type of vulnerability is CVE-2017-6890?
CVE-2017-6890 is classified as a boundary error vulnerability leading to a stack-based buffer overflow.
5
Can CVE-2017-6890 be exploited remotely?
Yes, CVE-2017-6890 can potentially be exploited remotely if an attacker can provide malicious input to the affected software.