It was found that phase_one_correct function does not handle memory object’s initialization correctly, which may have unspecified impact. Upstream patch: https://github.com/LibRaw/LibRaw/commit/89d065424f09b788f443734d44857289489ca9e2
Created LibRaw tracking bugs for this issue: Affects: fedora-all [bug 1287077]
Public via: http://seclists.org/fulldisclosure/2015/Nov/108