SUSE-SU-2018:3343-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3343-1
SUSE-SU-2018:3343-1
Summary: Security update for libraw
Details: This update for libraw fixes the following issues: Security issues fixed: - CVE-2018-5800: Fixed heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function (bsc#1084691). - CVE-2018-5801: Fixed NULL pointer dereference in LibRaw::unpack function (bsc#1084690). - CVE-2018-5802: Fixed out-of-bounds read in kodak_radc_load_raw function (bsc#1084688). - CVE-2018-5813: Fixed infinite loop in the parse_minolta function (bsc#1103200) - CVE-2018-5810: Fixed a heap-based buffer overflow in rollei_load_raw (bsc#1103353)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183343-1/, https://bugzilla.suse.com/1084688, https://bugzilla.suse.com/1084690, https://bugzilla.suse.com/1084691, https://bugzilla.suse.com/1103200, https://bugzilla.suse.com/1103353, https://www.suse.com/security/cve/CVE-2018-5800, https://www.suse.com/security/cve/CVE-2018-5801, https://www.suse.com/security/cve/CVE-2018-5802, https://www.suse.com/security/cve/CVE-2018-5810, https://www.suse.com/security/cve/CVE-2018-5813
Affected packages
Package
Name: libraw
Purl: pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
