First published: Sat Dec 22 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw Libraw | <=0.19.1 | |
debian/libraw | 0.20.2-1+deb11u1 0.20.2-2.1 0.21.2-2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20365 is a vulnerability in LibRaw::raw2image() in libraw_cxx.cpp that allows for a heap-based buffer overflow.
CVE-2018-20365 has a severity of 6.5 (Medium).
Libraw version 0.19.2-2, 0.19.2-2+deb10u4, 0.20.2-1+deb11u1, 0.20.2-2.1, and 0.21.1-7 are affected on Debian. libraw version 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1, 0.19.2-2, and 0.17.1-1ubuntu0.5 are affected on Ubuntu. The vulnerability affects Libraw version up to and including 0.19.1 on all platforms.
Apply the following remedies on Debian: libraw version 0.19.2-2 or later.
Apply the following remedies on Ubuntu: libraw version 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1, 0.19.2-2, or 0.17.1-1ubuntu0.5.