CVE-2018-19567: Buffer Overflow
Published Nov 26, 2018
·Updated
A floating point exception in parsetiffifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
Affected Software
1 affected component
Dcraw Project Dcraw<=9.28
Event History
Nov 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19567.
2
What is the severity level of CVE-2018-19567?
CVE-2018-19567 has a severity level of medium with a value of 5.5.
3
How can attackers exploit CVE-2018-19567?
Attackers can exploit CVE-2018-19567 by supplying malicious files to crash an application that uses dcraw through version 9.28.
4
Which software versions are affected by CVE-2018-19567?
All versions of dcraw up to and including 9.28 are affected by CVE-2018-19567.
5
Is there a fix available for CVE-2018-19567?
Yes, make sure to update to a version of dcraw that is after 9.28 to mitigate CVE-2018-19567.