cbcvebase.
CVE-2023-1729
published 2023-05-15

CVE-2023-1729: A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibraw< libraw 0.20.2-2.1 (bookworm)libraw 0.20.2-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
librawlibraw< 0.21.20.21.2
librawlibraw
librawlibraw>= 0 < 0.20.2-1+deb11u10.20.2-1+deb11u1
librawlibraw>= 0 < 0.20.2-2.10.20.2-2.1
librawlibraw>= 0 < 0.20.2-2.10.20.2-2.1
librawlibraw>= 0 < 0.20.2-2.10.20.2-2.1
linuxlinux_kernel>= 5.18.0 < 6.5.46.5.4
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM