CVE-2018-20337: Buffer Overflow
Last updated 11 July 2025
Other sources
There is a stack-based buffer overflow in the parsemakernote function of dcrawcommon.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20337?
CVE-2018-20337 is a vulnerability in LibRaw 0.19.1 that allows a crafted input to cause a denial of service or other unspecified impact.
What is the severity of CVE-2018-20337?
CVE-2018-20337 has a severity of 8.8, which is considered high.
How does CVE-2018-20337 affect LibRaw?
CVE-2018-20337 affects LibRaw 0.19.1 and possibly other versions.
How can I fix CVE-2018-20337 on Ubuntu?
You can fix CVE-2018-20337 on Ubuntu by updating to version 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1, or 0.19.2, depending on your Ubuntu release.
How can I fix CVE-2018-20337 on Debian?
For Debian, you can fix CVE-2018-20337 by updating to version 0.19.2-2, 0.19.2-2+deb10u4, 0.20.2-1+deb11u1, 0.20.2-2.1, or 0.21.1-7 of the libraw package.