CVE-2015-8367Improper Initialization in Libraw

Severity
9.8CRITICALNVD
EPSS
1.8%
top 17.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 24

Description

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

NVDlibraw/libraw< 0.17.1
debiandebian/libraw< darktable 2.0.0-1 (bookworm)
Debianlibraw/libraw< 0.17.1-1+3
debiandebian/kodi< darktable 2.0.0-1 (bookworm)
debiandebian/dcraw< darktable 2.0.0-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-q6jq-567x-75gp: The phase_one_correct function in Libraw before 02022-05-24
OSV
CVE-2015-8367: The phase_one_correct function in Libraw before 02020-01-14

📋Vendor Advisories

3
Ubuntu
LibRaw vulnerabilities2017-11-22
Red Hat
LibRaw: Memory objects are not intialized properly2015-11-30
Debian
CVE-2015-8367: darktable - The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause...2015

💬Community

2
Bugzilla
CVE-2015-8367 LibRaw: Memory objects are not intialized properly2015-12-01
Bugzilla
CVE-2015-8367 LibRaw: Memory objects are not intialized properly [fedora-all]2015-12-01