CVE-2018-19568
published 2018-11-26CVE-2018-19568: A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.92%
56.3th percentile
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dcraw_project | dcraw | <= 9.28 | — |
| debian | dcraw | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dcraw: A floating point exception in kodak_radc_load_raw resulting in a denial of service
vendor_redhat·2018-11-23·CVSS 5.5
CVE-2018-19568 [MEDIUM] CWE-369 dcraw: A floating point exception in kodak_radc_load_raw resulting in a denial of service
dcraw: A floating point exception in kodak_radc_load_raw resulting in a denial of service
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
Package: dcraw (Red Hat Enterprise Linux 5) - Will not fix
Package: dcraw (Red Hat Enterprise Linux 6) - Will not fix
Package: dcraw (Red Hat Enterprise Linux 7) - Fix deferred
Package: dcraw (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2018-19568: dcraw - A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be...
vendor_debian·2018·CVSS 5.5
CVE-2018-19568 [MEDIUM] CVE-2018-19568: dcraw - A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be...
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-j78c-p6vw-qcr3: A floating point exception in kodak_radc_load_raw in dcraw through 9
ghsa_unreviewed·2022-05-14
CVE-2018-19568 [MEDIUM] CWE-119 GHSA-j78c-p6vw-qcr3: A floating point exception in kodak_radc_load_raw in dcraw through 9
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
OSV
CVE-2018-19568: A floating point exception in kodak_radc_load_raw in dcraw through 9
osv·2018-11-26·CVSS 5.5
CVE-2018-19568 [MEDIUM] CVE-2018-19568: A floating point exception in kodak_radc_load_raw in dcraw through 9
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.
No detection rules found.
No public exploits indexed.
2018-11-26
Published