CVE-2018-19655: Buffer Overflow
Published Feb 10, 2018
·Updated
A stack-based buffer overflow in the findgreen() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
Affected Software
7 affected componentsFixes available
debian/dcraw
9.28-29.28-39.28-7
Dcraw Project Dcraw<=9.28
SUSE SUSE Linux Enterprise Desktop=12-sp3
SUSE SUSE Linux Enterprise Desktop=12-sp4
SUSE SUSE Linux Enterprise Server=11-sp4
SUSE SUSE Linux Enterprise Server=12-sp3
SUSE SUSE Linux Enterprise Server=12-sp4
Event History
Feb 10, 2018
Data Sourced
11:54 PM
SeverityAffected Software
Nov 29, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-19655?
CVE-2018-19655 is a vulnerability that allows a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
2
How does CVE-2018-19655 affect dcraw?
CVE-2018-19655 affects dcraw versions up to and including 9.28.
3
How does CVE-2018-19655 affect ufraw?
CVE-2018-19655 affects ufraw version 0.22-4.
4
Is there a fix available for CVE-2018-19655 in dcraw?
Yes, the vulnerability has been patched in dcraw versions 9.28-2 and 9.28-3.
5
Is there a fix available for CVE-2018-19655 in ufraw?
Yes, the vulnerability has been patched in ufraw version 0.22-4.