Stack-Based Buffer Overflow in LibRaw Affects Multiple Versions
CVE-2018-10528

8.8HIGH

Key Information:

Vendor
Canonical
Vendor
CVE Published:
29 April 2018

Summary

A stack-based buffer overflow vulnerability exists in the utf2char function located in libraw_cxx.cpp within LibRaw 0.18.9. An attacker may exploit this weakness to potentially execute arbitrary code or crash the application, leading to significant security risks. It is crucial for users to apply available patches or upgrade to secure versions to mitigate the potential impact of this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.