Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0356
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0356)
Resumen:The remote host is missing an update for the 'libraw' package(s) announced via the MGASA-2018-0356 advisory.
Descripción:Summary:
The remote host is missing an update for the 'libraw' package(s) announced via the MGASA-2018-0356 advisory.

Vulnerability Insight:
This update provides libraw 0.18.13 fixing at least the following
security issues:

LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow
in the internal/dcraw_common.cpp:parse_qt() function. An attacker could
exploit this to cause an infinite loop via a specially crafted Apple
QuickTime file (CVE-2018-5815).

LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow
in the internal/dcraw_common.cpp:identify() function. An attacker could
exploit this to cause an divide-by-zero and resultant denial of service
via a specially crafted NOKIARAW file (CVE-2018-5816).

libraw 0.18.13 adds fixes for:
* possible stack overrun while reading zero-sized strings
* possible integer overflow

Affected Software/OS:
'libraw' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.1

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2018-5815
https://github.com/LibRaw/LibRaw/blob/master/Changelog.txt
https://github.com/LibRaw/LibRaw/commit/1334647862b0c90b2e8cb2f668e66627d9517b17
https://secuniaresearch.flexerasoftware.com/secunia_research/2018-14/
https://secuniaresearch.flexerasoftware.com/advisories/83507/
https://usn.ubuntu.com/3838-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-5816
https://github.com/LibRaw/LibRaw/commit/1d8d1b452e5dc74033ee9f846081a0efb616cc39
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.