cbcvebase.
CVE-2018-19655
published 2018-11-29

CVE-2018-19655: A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker…

PriorityP346high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.85%
85.1th percentile
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

Affected

9 ranges
VendorProductVersion rangeFixed in
dcraw_projectdcraw<= 9.28
dcraw_projectdcraw>= 0 < 9.28-29.28-2
dcraw_projectdcraw>= 0 < 9.28-29.28-2
dcraw_projectdcraw>= 0 < 9.28-29.28-2
dcraw_projectdcraw>= 0 < 9.28-29.28-2
debiandcraw< dcraw 9.28-2 (bookworm)dcraw 9.28-2 (bookworm)
susesuse_linux_enterprise_desktop
susesuse_linux_enterprise_server
susesuse_linux_enterprise_server

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.