CVE-2018-5813
published 2018-12-07CVE-2018-5813: An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.09%
79.6th percentile
An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libraw | < libraw 0.18.11-1 (bookworm) | libraw 0.18.11-1 (bookworm) |
| libraw | libraw | < 0.18.11 | 0.18.11 |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
| libraw | libraw | >= 0 < 0.18.11-1 | 0.18.11-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2018-12-06
CVE-2018-5807 LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: LibRaw could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo file, a
remote attacker could cause applications linked against LibRaw to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all the
necessary changes.
Red Hat
libRaw: infinite loop in the parse_minolta function in dcraw/dcraw.c
vendor_redhat·2018-07-19·CVSS 6.5
CVE-2018-5813 [MEDIUM] CWE-835 libRaw: infinite loop in the parse_minolta function in dcraw/dcraw.c
libRaw: infinite loop in the parse_minolta function in dcraw/dcraw.c
An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
Statement: This issue affects the versions of LibRaw as shipped with Red Hat Enterprise Linux 7.
Package: LibRaw (Red Hat Enterprise Linux 7) - Will not fix
Package: LibRaw (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2018-5813: libraw - An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw version...
vendor_debian·2018·CVSS 6.5
CVE-2018-5813 [MEDIUM] CVE-2018-5813: libraw - An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw version...
An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
Scope: local
bookworm: resolved (fixed in 0.18.11-1)
bullseye: resolved (fixed in 0.18.11-1)
forky: resolved (fixed in 0.18.11-1)
sid: resolved (fixed in 0.18.11-1)
trixie: resolved (fixed in 0.18.11-1)
GHSA
GHSA-gxrc-xc5x-p823: An error within the "parse_minolta()" function (dcraw/dcraw
ghsa_unreviewed·2022-05-13
CVE-2018-5813 [HIGH] CWE-835 GHSA-gxrc-xc5x-p823: An error within the "parse_minolta()" function (dcraw/dcraw
An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
OSV
CVE-2018-5813: An error within the "parse_minolta()" function (dcraw/dcraw
osv·2018-12-07·CVSS 6.5
CVE-2018-5813 [MEDIUM] CVE-2018-5813: An error within the "parse_minolta()" function (dcraw/dcraw
An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
No detection rules found.
No public exploits indexed.
https://github.com/LibRaw/LibRaw/blob/master/Changelog.txthttps://github.com/LibRaw/LibRaw/commit/e47384546b43d0fd536e933249047bc397a4d88bhttps://secuniaresearch.flexerasoftware.com/advisories/83050/https://secuniaresearch.flexerasoftware.com/secunia_research/2018-13/https://usn.ubuntu.com/3838-1/https://github.com/LibRaw/LibRaw/blob/master/Changelog.txthttps://github.com/LibRaw/LibRaw/commit/e47384546b43d0fd536e933249047bc397a4d88bhttps://secuniaresearch.flexerasoftware.com/advisories/83050/https://secuniaresearch.flexerasoftware.com/secunia_research/2018-13/https://usn.ubuntu.com/3838-1/
2018-12-07
Published