RHSA-2024:2137: Low: LibRaw security update
LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).Security Fix(es): LibRaw: a heap-buffer-overflow in raw2imageex() (CVE-2023-1729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2137?
The severity of RHSA-2024:2137 is critical due to a heap buffer overflow in the LibRaw library.
How do I fix RHSA-2024:2137?
To fix RHSA-2024:2137, you need to update your affected Red Hat packages immediately.
Which products are affected by RHSA-2024:2137?
RHSA-2024:2137 affects multiple Red Hat products including Red Hat Enterprise Linux for x86_64 and Red Hat CodeReady Linux Builder.
What is the impact of the vulnerability RHSA-2024:2137?
The impact of RHSA-2024:2137 includes potential exploitation leading to application crashes or arbitrary code execution.
Is there a proof of concept available for RHSA-2024:2137?
Currently, there are no publicly disclosed proof of concept exploits for RHSA-2024:2137.