CVE-2018-19568: Buffer Overflow
Published Nov 26, 2018
·Updated
A floating point exception in kodakradcloadraw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
Affected Software
1 affected component
Dcraw Project Dcraw<=9.28
Event History
Nov 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-19568.
2
What is the severity level of CVE-2018-19568?
The severity level of CVE-2018-19568 is medium.
3
What is the affected software?
The affected software is Dcraw Project Dcraw version up to and including 9.28.
4
What could an attacker do with this vulnerability?
An attacker could use this vulnerability to crash an application that bundles the dcraw code by supplying malicious files.
5
Where can I find more information about CVE-2018-19568?
You can find more information about CVE-2018-19568 at the following links: [https://seclists.org/oss-sec/2018/q4/165](https://seclists.org/oss-sec/2018/q4/165) and [https://seclists.org/oss-sec/2018/q4/171](https://seclists.org/oss-sec/2018/q4/171)