CVE-2018-5805: Buffer Overflow
A boundary error within the "quicktake100loadraw()" function (internal/dcrawcommon.cpp) can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.
References:
https://secuniaresearch.flexerasoftware.com/secuniaresearch/2018-03
Other sources
A boundary error within the "quicktake100loadraw()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-5805?
CVE-2018-5805 is a vulnerability that exists in LibRaw versions prior to 0.18.8, which allows for a stack-based buffer overflow and subsequent crash.
How severe is CVE-2018-5805?
CVE-2018-5805 has a severity rating of 8.8 (high).
How can CVE-2018-5805 be exploited?
CVE-2018-5805 can be exploited by causing a stack-based buffer overflow.
Which software versions are affected by CVE-2018-5805?
LibRaw versions prior to 0.18.8 are affected by CVE-2018-5805.
How can I fix CVE-2018-5805?
To fix CVE-2018-5805, upgrade to LibRaw version 0.18.8 or later.