cbcvebase.

Debian Libraw vulnerabilities

54 known vulnerabilities affecting debian/libraw.

Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH16MEDIUM19LOW15

Vulnerabilities

Page 2 of 3
CVE-2018-20337P3HIGHCVSS 8.8fixed in libraw 0.19.2-1 (bookworm)2018
CVE-2018-20337 [HIGH] CVE-2018-20337: libraw - There is a stack-based buffer overflow in the parse_makernote function of dcraw_... There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.2-1) bullseye: resolved (fixed in 0.19.2-1) forky: resolved (fixed in 0.19.2-1) sid: resolved (fixed in 0.19.2-1) trixie: resolv
debian
CVE-2018-10529P3LOWCVSS 8.8fixed in libraw 0.18.11-1 (bookworm)2018
CVE-2018-10529 [HIGH] CVE-2018-10529: libraw - An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecti... An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and libraw_cxx.cpp. Scope: local bookworm: resolved (fixed in 0.18.11-1) bullseye: resolved (fixed in 0.18.11-1) forky: resolved (fixed in 0.18.11-1) sid: resolved (fixed in 0.18.11-1) trixie: resolved (fixed in 0.18.11-1)
debian
CVE-2018-5819P3HIGHCVSS 7.5fixed in libraw 0.19.1-1 (bookworm)2018
CVE-2018-5819 [HIGH] CVE-2018-5819: libraw - An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) with... An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources. Scope: local bookworm: resolved (fixed in 0.19.1-1) bullseye: resolved (fixed in 0.19.1-1) forky: resolved (fixed in 0.19.1-1) sid: resolved (fixed in 0.19.1-1) trixie: resolved (fixed in 0.19.1-1)
debian
CVE-2018-5817P3HIGHCVSS 7.5fixed in libraw 0.19.1-1 (bookworm)2018
CVE-2018-5817 [HIGH] CVE-2018-5817: libraw - A type confusion error within the "unpacked_load_raw()" function within LibRaw v... A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop. Scope: local bookworm: resolved (fixed in 0.19.1-1) bullseye: resolved (fixed in 0.19.1-1) forky: resolved (fixed in 0.19.1-1) sid: resolved (fixed in 0.19.1-1) trixie: resolved (fixed in 0.19.
debian
CVE-2018-5818P3HIGHCVSS 7.5fixed in libraw 0.19.1-1 (bookworm)2018
CVE-2018-5818 [HIGH] CVE-2018-5818: libraw - An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within... An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop. Scope: local bookworm: resolved (fixed in 0.19.1-1) bullseye: resolved (fixed in 0.19.1-1) forky: resolved (fixed in 0.19.1-1) sid: resolved (fixed in 0.19.1-1) trixie: resolved (fixed in 0.19.1-1)
debian
CVE-2025-43961P3LOWCVSS 2.9fixed in libraw 0.20.2-2.1+deb12u1 (bookworm)2025
CVE-2025-43961 [LOW] CVE-2025-43961: libraw - In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fuji... In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser. Scope: local bookworm: resolved (fixed in 0.20.2-2.1+deb12u1) bullseye: resolved (fixed in 0.20.2-1+deb11u2) forky: resolved (fixed in 0.21.4-1) sid: resolved (fixed in 0.21.4-1) trixie: resolved (fixed in 0.21.4-1)
debian
CVE-2017-6887P3HIGHCVSS 7.8fixed in libraw 0.18.2-2 (bookworm)2017
CVE-2017-6887 [HIGH] CVE-2017-6887: libraw - A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.c... A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs. Scope: local bookworm: resolved (fixed in 0.18.2-2) bullseye: resolved (fixed in
debian
CVE-2013-2126P3LOWCVSS 7.5fixed in darktable 1.2.1-2 (bookworm)2013
CVE-2013-2126 [HIGH] CVE-2013-2126: darktable - Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cx... Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file. Scope: local bookworm: resolved (fixed in 1.2.1-2) bullseye: resolved (fixed
debian
CVE-2017-13735P3LOWCVSS 7.5fixed in libraw 0.18.5-1 (bookworm)2017
CVE-2017-13735 [HIGH] CVE-2017-13735: libraw - There is a floating point exception in the kodak_radc_load_raw function in dcraw... There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of service attack. Scope: local bookworm: resolved (fixed in 0.18.5-1) bullseye: resolved (fixed in 0.18.5-1) forky: resolved (fixed in 0.18.5-1) sid: resolved (fixed in 0.18.5-1) trixie: resolved (fixed in 0.18.5-1)
debian
CVE-2020-24889P3HIGHCVSS 7.8fixed in libraw 0.20.2-1 (bookworm)2020
CVE-2020-24889 [HIGH] CVE-2020-24889: libraw - A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedMo... A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution. Scope: local bookworm: resolved (fixed in 0.20.2-1) bullseye: resolved (fixed in 0.20.2-1) forky: resolved (fixed in 0.20.2-1) sid: resolved (fixed in 0.20.2-1) trixie: resolved (fixed in 0.20.
debian
CVE-2018-5800P4MEDIUMCVSS 6.5fixed in libraw 0.18.7-1 (bookworm)2018
CVE-2018-5800 [MEDIUM] CVE-2018-5800: libraw - An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (intern... An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash. Scope: local bookworm: resolved (fixed in 0.18.7-1) bullseye: resolved (fixed in 0.18.7-1) forky: resolved (fixed in 0.18.7-1) sid: resolved (fixe
debian
CVE-2018-5815P4LOWCVSS 6.5fixed in libraw 0.18.13-1 (bookworm)2018
CVE-2018-5815 [MEDIUM] CVE-2018-5815: libraw - An integer overflow error within the "parse_qt()" function (internal/dcraw_commo... An integer overflow error within the "parse_qt()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file. Scope: local bookworm: resolved (fixed in 0.18.13-1) bullseye: resolved (fixed in 0.18.13-1) forky: resolved (fixed in 0.18.13-1) sid: resolved (fixed in 0
debian
CVE-2018-5816P4LOWCVSS 6.5fixed in libraw 0.18.13-1 (bookworm)2018
CVE-2018-5816 [MEDIUM] CVE-2018-5816: libraw - An integer overflow error within the "identify()" function (internal/dcraw_commo... An integer overflow error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger a division by zero via specially crafted NOKIARAW file (Note: This vulnerability is caused due to an incomplete fix of CVE-2018-5804). Scope: local bookworm: resolved (fixed in 0.18.13-1) bullseye: resolved (fixed in 0
debian
CVE-2018-5813P4LOWCVSS 6.5fixed in libraw 0.18.11-1 (bookworm)2018
CVE-2018-5813 [MEDIUM] CVE-2018-5813: libraw - An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw version... An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file. Scope: local bookworm: resolved (fixed in 0.18.11-1) bullseye: resolved (fixed in 0.18.11-1) forky: resolved (fixed in 0.18.11-1) sid: resolved (fixed in 0.18.11-1) trixie: resolved (fixed in 0.1
debian
CVE-2018-20365P4MEDIUMCVSS 6.5fixed in libraw 0.19.2-2 (bookworm)2018
CVE-2018-20365 [MEDIUM] CVE-2018-20365: libraw - LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow. LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.19.2-2) bullseye: resolved (fixed in 0.19.2-2) forky: resolved (fixed in 0.19.2-2) sid: resolved (fixed in 0.19.2-2) trixie: resolved (fixed in 0.19.2-2)
debian
CVE-2018-5812P4MEDIUMCVSS 6.5fixed in libraw 0.18.11-1 (bookworm)2018
CVE-2018-5812 [MEDIUM] CVE-2018-5812: libraw - An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.... An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to trigger a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.18.11-1) bullseye: resolved (fixed in 0.18.11-1) forky: resolved (fixed in 0.18.11-1) sid: resolved (fixed in 0.18.11-1) trixie: resolved (fixed in 0
debian
CVE-2018-5806P4LOWCVSS 6.5fixed in libraw 0.18.8-1 (bookworm)2018
CVE-2018-5806 [MEDIUM] CVE-2018-5806: libraw - An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) i... An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.18.8-1) bullseye: resolved (fixed in 0.18.8-1) forky: resolved (fixed in 0.18.8-1) sid: resolved (fixed in 0.18.8-1) trixie: resolved (fixed in 0.18.8-1)
debian
CVE-2023-1729P4MEDIUMCVSS 6.5fixed in libraw 0.20.2-2.1 (bookworm)2023
CVE-2023-1729 [MEDIUM] CVE-2023-1729: libraw - A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a... A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. Scope: local bookworm: resolved (fixed in 0.20.2-2.1) bullseye: resolved (fixed in 0.20.2-1+deb11u1) forky: resolved (fixed in 0.20.2-2.1) sid: resolved (fixed in 0.20.2-2.1) trixie: resolved (fixed in 0.20.2-2.1)
debian
CVE-2018-5801P4MEDIUMCVSS 6.5fixed in libraw 0.18.7-1 (bookworm)2018
CVE-2018-5801 [MEDIUM] CVE-2018-5801: libraw - An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw v... An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.18.7-1) bullseye: resolved (fixed in 0.18.7-1) forky: resolved (fixed in 0.18.7-1) sid: resolved (fixed in 0.18.7-1) trixie: resolved (fixed in 0.18.7-1)
debian
CVE-2018-5811P4MEDIUMCVSS 6.5fixed in libraw 0.18.11-1 (bookworm)2018
CVE-2018-5811 [MEDIUM] CVE-2018-5811: libraw - An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.... An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash. Scope: local bookworm: resolved (fixed in 0.18.11-1) bullseye: resolved (fixed in 0.18.11-1) forky: resolved (fixed in 0.18.11-1) sid: resolved (fixed in 0
debian
Debian Libraw vulnerabilities | cvebase