5.8
CVSSv2

CVE-2018-19566

Published: 26/11/2018 Updated: 19/12/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

A heap buffer over-read in parse_tiff_ifd in dcraw up to and including 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dcraw project dcraw

Vendor Advisories

A heap buffer over-read in parse_tiff_ifd in dcraw through 928 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information ...