LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow in the internal/dcraw_common.cpp:identify() function. An attacker could exploit this to cause an divide-by-zero and resultant denial of service via a specially crafted NOKIARAW file.
This vulnerability was caused by an incomplete fix to CVE-2018-5804.
Reference:
http://seclists.org/bugtraq/2018/Jul/58
Created LibRaw tracking bugs for this issue:
Affects: epel-6 [bug 1610159]
Affects: fedora-all [bug 1610157]
Created mingw-LibRaw tracking bugs for this issue:
Affects: fedora-all [bug 1610158]