CVE-2017-6890

CRITICAL

LibRaw-demosaic-pack-GPL2 <0.18.2 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer overflow.

References (2)

Core 2
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://secuniaresearch.flexerasoftware.com/advisories/75000/

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 63.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
libraw/libraw-demosaic-pack-gpl2 < 0.18.1
LibRaw/LibRaw-demosaic-pack-GPL2 0.x prior to 0.18.2
Published May 15, 2017
Tracked Since Feb 18, 2026