CVE-2018-19655
Dashboard / Vulnerabilities / CVE-2018-19655
CVE-2018-19655
Summary:
Details: A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
References: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3JX4A5F4DWP6NOEULXQXZ5AIH4GA62U/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RD65NMWZ5OQNUIF7CLGKLDG4LVPPMJY7/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XK4SHVVIZT6FHJVHOQSAFJMQWDLMWKDE/, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=890086, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906529
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
