9.8
CVSSv3

CVE-2017-6886

Published: 16/05/2017 Updated: 04/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.2 can be exploited to corrupt memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libraw libraw

Vendor Advisories

Debian Bug report logs - #864183 CVE-2017-6886 CVE-2017-6887 Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 4 Jun 2017 21:33:01 UTC Severity: grave Tags: security Fixed in ver ...
LibRaw could be made to crash or run programs as your login if it opened a specially crafted file ...
Hossein Lotfi and Jakub Jirasek from Secunia Research have discovered multiple vulnerabilities in LibRaw, a library for reading RAW images An attacker could cause a memory corruption leading to a DoS (Denial of Service) with craft KDC or TIFF file For the oldstable distribution (jessie), these problems have been fixed in version 0160-9+deb8u3 ...
An error within the "parse_tiff_ifd()" function (internal/dcraw_commoncpp) in LibRaw versions before 0182 can be exploited to corrupt memory ...