First published: Sun Apr 20 2025(Updated: )
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw | <0.21.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43964 is classified as a moderate severity vulnerability due to the lack of input validation affecting image processing.
To fix CVE-2025-43964, update LibRaw to version 0.21.4 or later, which addresses the issue with tag 0x412 processing.
CVE-2025-43964 affects LibRaw versions prior to 0.21.4.
The vulnerability may lead to incorrect image processing, resulting in potential data corruption or application crashes.
For more details on CVE-2025-43964, refer to the official release notes from LibRaw regarding version 0.21.4.