suse · CVE-2018-5802

Quick triage

Priority: low Published: 2021-05-30 14:09:44 UTC Updated: 2023-12-08 01:11:15 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-5802 severity low: SUSE including 5 source package names (libkdcraw-4.10.5-5.el7, libkdcraw-devel-4.10.5-5.el7, libraw-devel-0.15.4-21.1, libraw-devel-static-0.15.4-21.1, libraw9-0.15.4-21.1), 16 product×package rows across 9 product lines (SUSE Liberty Linux 7, SUSE Linux Enterprise Desktop 12 SP3, … (9 product lines)): Fixed 16.

Description:

An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

cvelogic Threat Intelligence