Red Hat Bugzilla – Bug 1553332
CVE-2018-5800 LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp
Last modified: 2018-10-30 03:28:54 EDT
An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) can be exploited to cause a heap-based buffer overflow and subsequently cause a crash. External References: https://packetstormsecurity.com/files/146172/secunia-libraw.txt Upstream Patch: https://github.com/LibRaw/LibRaw/commit/8682ad204392b91
This was fixed in LibRaw-0.18.7. The commit message has 7 typoed as 17.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:3065 https://access.redhat.com/errata/RHSA-2018:3065