CVE-2017-6889

CRITICAL

LibRaw-demosaic-pack-GPL2 <0.18.2 - Buffer Overflow

Title source: llm
STIX 2.1

Description

An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.

References (2)

Core 2
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://secuniaresearch.flexerasoftware.com/advisories/75000/

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 63.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (2)
libraw/libraw-demosaic-pack-gpl2 < 0.18.1
LibRaw/LibRaw-demosaic-pack-GPL2 0.x prior to 0.18.2
Published May 15, 2017
Tracked Since Feb 18, 2026