6.4
CVSSv2

CVE-2017-14608

Published: 20/09/2017 Updated: 27/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

In LibRaw up to and including 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libraw libraw

Vendor Advisories

LibRaw could be made to crash or run programs as your login if it opened a specially crafted file ...
In LibRaw through 0184, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcrawc and internal/dcraw_commoncpp An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash ...