VulnerabilityModified
CVE-2018-19565
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
HIGH 7.1EPSS 1.07%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
- CVSS 3.0
- 7.1 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- dcraw project/dcraw
- Source
- cve@mitre.org
References
- https://seclists.org/oss-sec/2018/q4/165Mailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q4/171Mailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q4/165Mailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q4/171Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.