Bug 2361287 (CVE-2025-43964)
Summary: | CVE-2025-43964 LibRaw: Improper Validation of Specified Quantity in Input in LibRaw | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | Keywords: | Security |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | --- | |
Doc Text: |
A flaw was found in LibRaw. In affected versions, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2361349, 2361350, 2361358, 2361363, 2361351, 2361352, 2361353, 2361354, 2361355, 2361356, 2361357, 2361359, 2361360, 2361361, 2361362, 2361364, 2361365, 2361366 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2025-04-21 00:01:18 UTC
|