CVE-2018-5806
published 2018-12-07CVE-2018-5806: An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.69%
74.7th percentile
An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libraw | < libraw 0.18.8-1 (bookworm) | libraw 0.18.8-1 (bookworm) |
| libraw | libraw | < 0.18.8 | 0.18.8 |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.18.8-1 | 0.18.8-1 |
| libraw | libraw | >= 0 < 0.18.8-1 | 0.18.8-1 |
| libraw | libraw | >= 0 < 0.18.8-1 | 0.18.8-1 |
| libraw | libraw | >= 0 < 0.18.8-1 | 0.18.8-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcxg-6ffh-5mqj: An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common
ghsa_unreviewed·2022-05-14
CVE-2018-5806 [MEDIUM] CWE-476 GHSA-hcxg-6ffh-5mqj: An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common
An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.
OSV
CVE-2018-5806: An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common
osv·2018-12-07·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806: An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common
An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.
Red Hat
LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp
vendor_redhat·2018-03-14·CVSS 6.5
CVE-2018-5806 [MEDIUM] CWE-476 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp
LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp
An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.
A NULL pointer dereference vulnerability in internal/dcraw_common.cpp:leaf_hdr_load_raw() function was found in LibRaw. A user can cause a denial of service when processing specially-crafted RAW data.
Statement: This issue did not affect the versions of dcraw as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include the vulnerable code.
This issue did not affect the versions of LibRaw as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.
Package: dcraw (Red Hat Enterprise Linux
Debian
CVE-2018-5806: libraw - An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) i...
vendor_debian·2018·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806: libraw - An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) i...
An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.18.8-1)
bullseye: resolved (fixed in 0.18.8-1)
forky: resolved (fixed in 0.18.8-1)
sid: resolved (fixed in 0.18.8-1)
trixie: resolved (fixed in 0.18.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5806 rawtherapee: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 rawtherapee: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
CVE-2018-5806 rawtherapee: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2018-5806 dcraw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 dcraw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
CVE-2018-5806 dcraw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2018-5806 libkdcraw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 libkdcraw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
CVE-2018-5806 libkdcraw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [epel-6]
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [epel-6]
CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp
CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp
An error within the "leaf_hdr_load_raw()" function
(internal/dcraw_common.cpp) can be exploited to trigger a NULL pointer
dereference.
References:
https://secuniaresearch.flexerasoftware.com/secunia_research/2018-03
Discussion:
Created LibRaw tracking bugs for this issue:
Affects: epel-6 [bug 1591900]
Affects: fedora-all [bug 1591899]
Created dcraw tracking bugs for this issue:
Affects: fedora-all [bug 1591901]
Created libkdcraw tracking bugs for this issue:
Affects: fedora-all [bug 1591903]
Created mingw-LibRaw tracking bugs for this issue:
Affects: fedora-all [bug 1591902]
Created rawtherapee tracking bugs for this issue:
Affects: fedora-all [bug 1591898]
---
Up
Bugzilla
CVE-2018-5806 mingw-LibRaw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
bugzilla·2018-06-15·CVSS 6.5
CVE-2018-5806 [MEDIUM] CVE-2018-5806 mingw-LibRaw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
CVE-2018-5806 mingw-LibRaw: LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
https://access.redhat.com/errata/RHSA-2018:3065https://github.com/LibRaw/LibRaw/blob/master/Changelog.txthttps://github.com/LibRaw/LibRaw/commit/9f26ce37f5be86ea11bfc6831366558650b1f6ffhttps://secuniaresearch.flexerasoftware.com/advisories/81000/https://secuniaresearch.flexerasoftware.com/secunia_research/2018-3/https://access.redhat.com/errata/RHSA-2018:3065https://github.com/LibRaw/LibRaw/blob/master/Changelog.txthttps://github.com/LibRaw/LibRaw/commit/9f26ce37f5be86ea11bfc6831366558650b1f6ffhttps://secuniaresearch.flexerasoftware.com/advisories/81000/https://secuniaresearch.flexerasoftware.com/secunia_research/2018-3/
2018-12-07
Published