CVE-2018-5800: Buffer Overflow
An off-by-one error within the "LibRaw::kodakycbcrloadraw()" function (internal/dcrawcommon.cpp) can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
External References:
https://packetstormsecurity.com/files/146172/secunia-libraw.txt
Upstream Patch:
https://github.com/LibRaw/LibRaw/commit/8682ad204392b91
Other sources
An off-by-one error within the "LibRaw::kodakycbcrloadraw()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-5800?
CVE-2018-5800 refers to an off-by-one error within the LibRaw::kodak_ycbcr_load_raw() function, which can lead to a heap-based buffer overflow and crash.
How severe is CVE-2018-5800?
CVE-2018-5800 has a severity rating of 6.5 out of 10.
What software versions are affected by CVE-2018-5800?
LibRaw versions prior to 0.18.7 are affected by CVE-2018-5800.
How can I fix CVE-2018-5800?
To fix CVE-2018-5800, update to LibRaw version 0.18.7 or later.
Where can I find more information about CVE-2018-5800?
You can find more information about CVE-2018-5800 at the following references: [1](http://www.securityfocus.com/bid/104663), [2](https://access.redhat.com/errata/RHSA-2018:3065), [3](https://github.com/LibRaw/LibRaw/blob/master/Changelog.txt)