Description
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/oss-sec/2018/q4/165
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/oss-sec/2018/q4/171
Scores
CVSS v3
7.1
EPSS
0.0030
EPSS Percentile
53.0%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (1)
dcraw_project/dcraw
< 9.28
Published
Nov 26, 2018
Tracked Since
Feb 18, 2026