REDHAT-BUG-2455925: Buffer Overflow
An integer overflow vulnerability exists in the uncompressedfpdngloadraw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2455925?
The severity of REDHAT-BUG-2455925 is classified as high due to the potential for a heap buffer overflow.
How do I fix REDHAT-BUG-2455925?
To fix REDHAT-BUG-2455925, update LibRaw to a version that includes the security patch addressing the integer overflow.
What types of systems are affected by REDHAT-BUG-2455925?
REDHAT-BUG-2455925 affects systems running LibRaw version 8dc68e2.
What risks are associated with REDHAT-BUG-2455925?
Risks associated with REDHAT-BUG-2455925 include potential remote code execution if an attacker provides a specially crafted file.
How does REDHAT-BUG-2455925 manifest in an application?
REDHAT-BUG-2455925 can manifest as application crashes or unexpected behavior when handling maliciously crafted files.