View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2018-5802 severity low: SUSE including 5 source package names (libkdcraw-4.10.5-5.el7, libkdcraw-devel-4.10.5-5.el7, libraw-devel-0.15.4-21.1, libraw-devel-static-0.15.4-21.1, libraw9-0.15.4-21.1), 16 product×package rows across 9 product lines (SUSE Liberty Linux 7, SUSE Linux Enterprise Desktop 12 SP3, … (9 product lines)): Fixed 16.
An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.