Source: libraw
Version: 0.18.2-2
Severity: normal
Tags: security patch upstream
Forwarded: https://github.com/LibRaw/LibRaw/issues/96

There is a floating point exception in the kodak_radc_load_raw function in
dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of service
attack.

https://nvd.nist.gov/vuln/detail/CVE-2017-13735
https://github.com/LibRaw/LibRaw/issues/96
https://bugzilla.redhat.com/show_bug.cgi?id=1483988

This has been fixed in upstream 0.18.3 release. Please see:
https://www.libraw.org/news/libraw-0-18-3

-- 
Henri Salo

Attachment: signature.asc
Description: PGP signature

Reply via email to