debian · CVE-2018-19565

Quick triage

Priority: unimportant Published: Updated: Sun, 28 Jun 2026 03:01:32 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-19565 unimportant priority: Debian including 1 source packages (dcraw), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5.

Description:

A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

cvelogic Threat Intelligence