Debian Libraw vulnerabilities
54 known vulnerabilities affecting debian/libraw.
Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH16MEDIUM19LOW15
Vulnerabilities
Page 3 of 3
CVE-2018-5804P4LOWCVSS 6.5fixed in libraw 0.18.8-1 (bookworm)2018
CVE-2018-5804 [MEDIUM] CVE-2018-5804: libraw - A type confusion error within the "identify()" function (internal/dcraw_common.c...
A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.
Scope: local
bookworm: resolved (fixed in 0.18.8-1)
bullseye: resolved (fixed in 0.18.8-1)
forky: resolved (fixed in 0.18.8-1)
sid: resolved (fixed in 0.18.8-1)
trixie: resolved (fixed in 0.18.8-1)
debian
CVE-2020-22628P4MEDIUMCVSS 6.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-22628 [MEDIUM] CVE-2020-22628: libraw - Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postpr...
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
debian
CVE-2017-16910P4MEDIUMCVSS 6.5fixed in libraw 0.18.6-1 (bookworm)2017
CVE-2017-16910 [MEDIUM] CVE-2017-16910: libraw - An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_comm...
An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.
Scope: local
bookworm: resolved (fixed in 0.18.6-1)
bullseye: resolved (fixed in 0.18.6-1)
forky: resolved (fixed in 0.18.6-1)
sid: resolved
debian
CVE-2018-20363P4MEDIUMCVSS 6.5fixed in libraw 0.19.2-2 (bookworm)2018
CVE-2018-20363 [MEDIUM] CVE-2018-20363: libraw - LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer derefere...
LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.19.2-2)
bullseye: resolved (fixed in 0.19.2-2)
forky: resolved (fixed in 0.19.2-2)
sid: resolved (fixed in 0.19.2-2)
trixie: resolved (fixed in 0.19.2-2)
debian
CVE-2018-20364P4MEDIUMCVSS 6.5fixed in libraw 0.19.2-2 (bookworm)2018
CVE-2018-20364 [MEDIUM] CVE-2018-20364: libraw - LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer derefer...
LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.19.2-2)
bullseye: resolved (fixed in 0.19.2-2)
forky: resolved (fixed in 0.19.2-2)
sid: resolved (fixed in 0.19.2-2)
trixie: resolved (fixed in 0.19.2-2)
debian
CVE-2015-3885P4MEDIUMCVSS 4.3fixed in darktable 1.6.7-1 (bookworm)2015
CVE-2015-3885 [MEDIUM] CVE-2015-3885: darktable - Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows re...
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
Scope: local
bookworm: resolved (fixed in 1.6.7-1)
bullseye: resolved (fixed in 1.6.7-1)
forky: resolved (fixed in 1.6.7-1)
sid: resolved (fixed in 1.
debian
CVE-2020-35530P4MEDIUMCVSS 5.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-35530 [MEDIUM] CVE-2020-35530: libraw - In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()"...
In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20
debian
CVE-2020-35534P4MEDIUMCVSS 5.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-35534 [MEDIUM] CVE-2020-35534: libraw - In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubband...
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
debian
CVE-2020-35535P4MEDIUMCVSS 5.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-35535 [MEDIUM] CVE-2020-35535: libraw - In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::pars...
In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
debian
CVE-2020-35531P4MEDIUMCVSS 5.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-35531 [MEDIUM] CVE-2020-35531: libraw - In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_dif...
In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
debian
CVE-2020-35533P4MEDIUMCVSS 5.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-35533 [MEDIUM] CVE-2020-35533: libraw - In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_...
In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-
debian
CVE-2020-35532P4MEDIUMCVSS 5.5fixed in libraw 0.20.0-4 (bookworm)2020
CVE-2020-35532 [MEDIUM] CVE-2020-35532: libraw - In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_...
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trix
debian
CVE-2013-1439P4MEDIUMCVSS 4.3fixed in darktable 1.2.2-2 (bookworm)2013
CVE-2013-1439 [MEDIUM] CVE-2013-1439: darktable - The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 al...
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Scope: local
bookworm: resolved (fixed in 1.2.2-2)
bullseye: resolved (fixed in 1.2.2-2)
forky: resolved (fixed in 1.2.2-2)
sid: resolved (fixed in 1.2.2-2)
trixie: resolv
debian
CVE-2013-1438P4MEDIUMCVSS 4.3fixed in darktable 1.2.2-2 (bookworm)2013
CVE-2013-1438 [MEDIUM] CVE-2013-1438: darktable - Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw...
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 1.2.2-2)
bullseye: resolved (fixed
debian
← Previous3 / 3