CVE-2018-20337

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
21/12/2018
Last modified:
24/08/2020

Description

There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libraw:libraw:0.19.1:*:*:*:*:*:*:*