Mageia 2022-0160: dcraw security update
Summary
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be
used by attackers able to supply malicious files to crash an application
that bundles the dcraw code or leak private information. (CVE-2018-19565)
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be
used by attackers able to supply malicious files to crash an application
that bundles the dcraw code or leak private information. (CVE-2018-19566)
A floating point exception in parse_tiff_ifd in dcraw through 9.28 could
be used by attackers able to supply malicious files to crash an application
that bundles the dcraw code. (CVE-2018-19567)
A floating point exception in kodak_radc_load_raw in dcraw through 9.28
could be used by attackers able to supply malicious files to crash an
application that bundles the dcraw code. (CVE-2018-19568)
A boundary error within the "quicktake_100_load_raw()" function
(internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be
exploited to cause a stack-ba...
References
- https://bugs.mageia.org/show_bug.cgi?id=24107
- https://www.openwall.com/lists/oss-security/2018/11/27/1
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YDVWQ5ZUMZUOMBBPVXPXX6XNCBNZ2BMJ/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5805
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5806
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19565
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19566
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19567
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19568
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3624
Resolution
MGASA-2022-0160 - Updated dcraw packages fix security vulnerability
SRPMS
- 8/core/dcraw-9.28.0-6.1.mga8