CVE-2018-5802: High severity Libraw Libraw vulnerability
An error within the "kodakradcloadraw()" function (internal/dcrawcommon.cpp) related to the "buf" variable can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.
External References:
https://packetstormsecurity.com/files/146172/secunia-libraw.txt
Upstream Patch:
https://github.com/LibRaw/LibRaw/commit/8682ad204392b91
Other sources
An error within the "kodakradcloadraw()" function (internal/dcrawcommon.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-5802?
CVE-2018-5802 is a vulnerability in LibRaw versions prior to 0.18.7 that can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.
What is the severity of CVE-2018-5802?
The severity of CVE-2018-5802 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2018-5802?
LibRaw versions prior to 0.18.7 are affected by CVE-2018-5802.
How can CVE-2018-5802 be fixed?
To fix CVE-2018-5802, update to LibRaw version 0.18.7 or higher.
Where can I find more information about CVE-2018-5802?
You can find more information about CVE-2018-5802 on the Red Hat Errata page and the LibRaw GitHub repository.