CVE-2018-5810
published 2018-12-07CVE-2018-5810: An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer…
PriorityP343high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.10%
79.6th percentile
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libraw | < libraw 0.18.11-1 (bookworm) | libraw 0.18.11-1 (bookworm) |
| libraw | libraw | < 0.18.9 | 0.18.9 |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j64j-33rm-7x57: An error within the "rollei_load_raw()" function (internal/dcraw_common
ghsa_unreviewed·2022-05-13
CVE-2018-5810 [HIGH] CWE-787 GHSA-j64j-33rm-7x57: An error within the "rollei_load_raw()" function (internal/dcraw_common
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
OSV
CVE-2018-5810: An error within the "rollei_load_raw()" function (internal/dcraw_common
osv·2018-12-07·CVSS 8.8
CVE-2018-5810 [HIGH] CVE-2018-5810: An error within the "rollei_load_raw()" function (internal/dcraw_common
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2018-12-06
CVE-2018-5807 LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: LibRaw could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo file, a
remote attacker could cause applications linked against LibRaw to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all the
necessary changes.
Red Hat
libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp
vendor_redhat·2018-05-30·CVSS 8.8
CVE-2018-5810 [HIGH] CWE-122 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp
libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
A heap-based buffer overflow has been discovered in LibRaw, in the way rollei_load_raw() function in internal/dcraw_common.cpp file handles the input image. An attacker could trigger the flaw by providing a specially crafted Rollei RAW Image, which could result in a crash or other unspecified effects.
Package: LibRaw (Red Hat Enterprise Linux 7) - Will not fix
Package: LibRaw (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-5810: libraw - An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in ...
vendor_debian·2018·CVSS 8.8
CVE-2018-5810 [HIGH] CVE-2018-5810: libraw - An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in ...
An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
Scope: local
bookworm: resolved (fixed in 0.18.11-1)
bullseye: resolved (fixed in 0.18.11-1)
forky: resolved (fixed in 0.18.11-1)
sid: resolved (fixed in 0.18.11-1)
trixie: resolved (fixed in 0.18.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5810 LibRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp [epel-6]
bugzilla·2020-04-22·CVSS 8.8
CVE-2018-5810 [HIGH] CVE-2018-5810 LibRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp [epel-6]
CVE-2018-5810 LibRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followi
Bugzilla
CVE-2018-5810 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp [epel-6]
bugzilla·2018-07-31·CVSS 8.8
CVE-2018-5810 [HIGH] CVE-2018-5810 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp [epel-6]
CVE-2018-5810 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followi
Bugzilla
CVE-2018-5810 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp
bugzilla·2018-07-31·CVSS 8.8
CVE-2018-5810 [HIGH] CVE-2018-5810 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp
CVE-2018-5810 libRaw: heap-based buffer overflow in rollei_load_raw in internal/dcraw_common.cpp
A flaw was found in LibRaw versions before 0.18.9. An error within the rollei_load_raw() function (internal/dcraw_common.cpp) can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
References:
https://secuniaresearch.flexerasoftware.com/secunia_research/2018-10/
Discussion:
Created LibRaw tracking bugs for this issue:
Affects: epel-6 [bug 1610480]
---
Upstream patch:
https://github.com/LibRaw/LibRaw/commit/c9d8143eba4ff397163665e2119c6c5d7db54c55
---
Function rollei_load_raw() does not check whether the index used to access the raw_image array is in bounds, thus a crafted raw image could cause a heap-based buffer overflow, which could result in a crash
https://github.com/LibRaw/LibRaw/blob/master/Changelog.txthttps://github.com/LibRaw/LibRaw/commit/fd6330292501983ac75fe4162275794b18445bd9https://secuniaresearch.flexerasoftware.com/advisories/81800/https://secuniaresearch.flexerasoftware.com/secunia_research/2018-10/https://usn.ubuntu.com/3838-1/https://github.com/LibRaw/LibRaw/blob/master/Changelog.txthttps://github.com/LibRaw/LibRaw/commit/fd6330292501983ac75fe4162275794b18445bd9https://secuniaresearch.flexerasoftware.com/advisories/81800/https://secuniaresearch.flexerasoftware.com/secunia_research/2018-10/https://usn.ubuntu.com/3838-1/
2018-12-07
Published