CVE-2018-5806: Null Pointer Dereference
Published Jun 15, 2018
·Updated
An error within the "leafhdrloadraw()" function (internal/dcrawcommon.cpp) can be exploited to trigger a NULL pointer dereference.
References:
https://secuniaresearch.flexerasoftware.com/secuniaresearch/2018-03
Other sources
An error within the "leafhdrloadraw()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.
— MITRE
Affected Software
5 affected componentsFixes available
redhat/LibRaw<0.18.8
0.18.8
Libraw Libraw<0.18.8
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Remediation
Event History
Dec 7, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
CVE-2018-5806
2
What is the severity level of CVE-2018-5806?
The severity level of CVE-2018-5806 is medium.
3
How can CVE-2018-5806 be exploited?
CVE-2018-5806 can be exploited by triggering a NULL pointer dereference.
4
What software versions of LibRaw are affected by CVE-2018-5806?
LibRaw versions up to 0.18.8 are affected by CVE-2018-5806.
5
How can I fix CVE-2018-5806?
To fix CVE-2018-5806, update to version 0.18.8 of LibRaw.