Bug 1494405 (CVE-2017-14265)
Summary: | CVE-2017-14265 libraw: Stack based buffer overflow in the xtrans_interpolate function | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | alekcejk, dchen, debarshir, dkholia, extras-orphan, fweimer, gwync, hobbes1069, jreznik, jridky, kde-sig, manisandro, mattdm, mattia.verga, nphilipp, rdieter, sebastian, siddharth.kde, than, thibault.north |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | libraw 0.18.3 | Doc Type: | If docs needed, set a value |
Doc Text: |
A stack buffer overflow flaw was found in the way dcraw handled processing of RAW image files. This flaw could potentially be used to crash the dcraw process by supplying it a specially crafted image file .
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2017-09-27 11:40:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1492123, 1492126, 1494406, 1499690 | ||
Bug Blocks: | 1494408 |
Description
Andrej Nemec
2017-09-22 08:24:34 UTC
Created LibRaw tracking bugs for this issue: Affects: epel-6 [bug 1494406] Created dcraw tracking bugs for this issue: Affects: fedora-all [bug 1492123] Created libkdcraw tracking bugs for this issue: Affects: fedora-all [bug 1492126] Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Created mingw-LibRaw tracking bugs for this issue: Affects: fedora-all [bug 1499690] |