Back

HIGH

libraw: Boundary error in the parse_tiff_ifd()

Published May 16, 2017

Description

A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published May 16, 2017
Updated Aug 5, 2024
Reserved Mar 14, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 11, 2017