USN-6137-1: LibRaw vulnerabilities
It was discovered that LibRaw incorrectly handled photo files. If a user or automated system were tricked into processing a specially crafted photo file, a remote attacker could cause applications linked against LibRaw to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6137-1?
The severity of USN-6137-1 is considered to be high due to the potential for denial of service and remote code execution.
How do I fix USN-6137-1?
To fix USN-6137-1, upgrade the libraw20 or libraw19 packages to the specified remedied versions for your Ubuntu release.
What are the affected versions in USN-6137-1?
Affected versions for USN-6137-1 include libraw20 versions prior to 0.20.2-2ubuntu2.23.04.1, 0.20.2-2ubuntu2.22.10.1, and 0.20.2-2ubuntu2.22.04.1, as well as libraw19 version up to 0.19.5-1ubuntu1.2.
What is the impact of USN-6137-1 vulnerability?
The impact of the USN-6137-1 vulnerability could allow an attacker to craft a malicious photo file that may crash applications using LibRaw or potentially execute arbitrary code.
Can USN-6137-1 be exploited remotely?
Yes, USN-6137-1 can be exploited remotely if a user or automated system processes a maliciously crafted photo file.