Memory Corruption Vulnerability in LibRaw Affecting Various TIFF Files
CVE-2017-6887
7.8HIGH
What is CVE-2017-6887?
A boundary error in the 'parse_tiff_ifd()' function of LibRaw prior to version 0.18.2 can lead to memory corruption when processing specially crafted KDC files. This vulnerability is particularly impactful when such files are created with specific model references, like 'DSLR-A100', and contain repeated sequences of TAGs 0x100 and 0x14A. Exploitation of this vulnerability can compromise system stability and lead to unauthorized access to sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LibRaw 0.x prior to 0.18.2
