CVE-2018-5815: Integer Overflow
An integer overflow error within the "parseqt()" function (internal/dcrawcommon.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-5815?
CVE-2018-5815 is an integer overflow error within the "parse_qt()" function in LibRaw versions prior to 0.18.12 that can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file.
How does CVE-2018-5815 affect LibRaw?
CVE-2018-5815 affects LibRaw versions prior to 0.18.12.
What is the severity of CVE-2018-5815?
The severity of CVE-2018-5815 is high with a CVSS score of 6.5.
How do I fix CVE-2018-5815 in LibRaw?
To fix CVE-2018-5815 in LibRaw, you need to update to version 0.18.12 or later.
Where can I find more information about CVE-2018-5815?
You can find more information about CVE-2018-5815 on the following references: [link1](https://github.com/LibRaw/LibRaw/blob/master/Changelog.txt), [link2](https://github.com/LibRaw/LibRaw/commit/1334647862b0c90b2e8cb2f668e66627d9517b17), [link3](https://secuniaresearch.flexerasoftware.com/advisories/83507/).