9.8
CVSSv3

CVE-2017-6886

Published: 16/05/2017 Updated: 04/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.2 can be exploited to corrupt memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libraw libraw

Vendor Advisories

LibRaw could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #864183 CVE-2017-6886 CVE-2017-6887 Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 4 Jun 2017 21:33:01 UTC Severity: grave Tags: security Fixed in ver ...
Hossein Lotfi and Jakub Jirasek from Secunia Research have discovered multiple vulnerabilities in LibRaw, a library for reading RAW images An attacker could cause a memory corruption leading to a DoS (Denial of Service) with craft KDC or TIFF file For the oldstable distribution (jessie), these problems have been fixed in version 0160-9+deb8u3 ...
An error within the "parse_tiff_ifd()" function (internal/dcraw_commoncpp) in LibRaw versions before 0182 can be exploited to corrupt memory ...