First published: Sun Apr 29 2018(Updated: )
An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and libraw_cxx.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libraw | 0.20.2-1+deb11u1 0.20.2-2.1 0.21.2-2.1 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =17.10 | |
Ubuntu Linux | =18.04 | |
LibRaw | =0.18.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10529 is a vulnerability in LibRaw 0.18.9 that allows for an out-of-bounds read affecting the X3F property table list implementation.
LibRaw versions 0.18.9 and prior are affected by CVE-2018-10529.
CVE-2018-10529 has a severity rating of 8.8, which is considered high.
To fix CVE-2018-10529, update your LibRaw installation to version 0.19.2 or later.
You can find more information about CVE-2018-10529 at the following references: [1](https://github.com/LibRaw/LibRaw/commit/f0c505a3e5d47989a5f69be2d0d4f250af6b1a6c), [2](https://github.com/LibRaw/LibRaw/issues/144), [3](https://usn.ubuntu.com/3639-1/).