CVE-2018-5804: Divide by Zero
Published Dec 7, 2018
·Updated
A type confusion error within the "identify()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.
Affected Software
1 affected component
Libraw Libraw<0.18.8
Remediation
Event History
Dec 7, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-5804?
CVE-2018-5804 is a vulnerability in LibRaw versions prior to 0.18.8 that allows an attacker to trigger a division by zero by exploiting a type confusion error in the "identify()" function.
2
How severe is CVE-2018-5804?
CVE-2018-5804 has a severity score of 6.5 (medium).
3
How can I exploit CVE-2018-5804?
To exploit CVE-2018-5804, an attacker needs to trigger a division by zero by exploiting the type confusion error in the "identify()" function of LibRaw.
4
What is the affected software?
The affected software is LibRaw versions prior to 0.18.8.
5
How can I fix CVE-2018-5804?
To fix CVE-2018-5804, update LibRaw to version 0.18.8 or later.
6
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-5804?
The CWE ID for CVE-2018-5804 is CWE-369 and CWE-704.