CVE-2018-5801: Null Pointer Dereference
An error within the "LibRaw::unpack()" function (src/librawcxx.cpp) can be exploited to trigger a NULL pointer dereference.
External References:
https://packetstormsecurity.com/files/146172/secunia-libraw.txt
Upstream Patch:
https://github.com/LibRaw/LibRaw/commit/8682ad204392b91
Other sources
An error within the "LibRaw::unpack()" function (src/librawcxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-5801?
CVE-2018-5801 is a vulnerability in the LibRaw library that allows an attacker to trigger a NULL pointer dereference.
How severe is CVE-2018-5801?
CVE-2018-5801 has a severity rating of 6.5, which is considered medium.
Which versions of LibRaw are affected by CVE-2018-5801?
Versions of LibRaw prior to 0.18.7 are affected by CVE-2018-5801.
How can I fix CVE-2018-5801?
To fix CVE-2018-5801, update LibRaw to version 0.18.7 or later.
Where can I find more information about CVE-2018-5801?
You can find more information about CVE-2018-5801 at the following references: [link1](https://access.redhat.com/errata/RHSA-2018:3065), [link2](https://github.com/LibRaw/LibRaw/blob/master/Changelog.txt), [link3](https://github.com/LibRaw/LibRaw/commit/0df5490b985c419de008d32168650bff17128914).