VDB
CVE-2015-8366
CVE-2015-8366
PUBLISHED
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.
EPSS 5.25% · 90.2th percentile
Risk Scores
EPSS Score
5.25%
90.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | exactimage | 0, 1.0.2-5ubuntu2, 1.0.2-7ubuntu2 |
| Ubuntu:22.04:LTS | rawtherapee | 5.8-3, 0 |
| Ubuntu:18.04:LTS | darktable | 2.2.5-2, 2.4.1-1, 0 |
| Ubuntu:16.04:LTS | kodi | *, 0, 15.1+dfsg1-3 |
| Ubuntu:20.04:LTS | kodi | 2:17.6+dfsg1-4ubuntu4, *, * |
| Ubuntu:24.04:LTS | darktable | 0, 4.4.2-1ubuntu2, 4.4.2-1ubuntu1 |
| Ubuntu:18.04:LTS | dcraw | 9.27-1ubuntu1, 0 |
| Ubuntu:25.10 | darktable | 0, 5.0.1-1, 5.0.1-2 |
| Ubuntu:16.04:LTS | darktable | 1.6.9-1, 2.0.0-1, 2.0.1-1 |
| Ubuntu:16.04:LTS | ufraw | 0, 0.20-3build1 |
| Ubuntu:16.04:LTS | dcraw | 9.21-0.2, 0 |
| Ubuntu:24.04:LTS | kodi | 0, 2:20.5+dfsg-1ubuntu1, 2:20.5+dfsg-1build2 |
| Ubuntu:24.04:LTS | rawtherapee | 5.10-1build3, 5.9-2, 5.10-1 |
| Ubuntu:18.04:LTS | rawtherapee | 5.2-1, 5.3-1, 0 |
| Ubuntu:25.10 | rawtherapee | 5.11-2build2, 0 |
| Ubuntu:16.04:LTS | exactimage | 0.9.1-8ubuntu1, 0.9.1-11, 0.9.1-12ubuntu1 |
| Ubuntu:24.04:LTS | exactimage | 1.0.2-11build2, 1.0.2-11build3, 1.0.2-11build4 |
| Ubuntu:25.10 | kodi | 0, 2:21.2+dfsg-4build1, 2:21.2+dfsg-4 |
| Ubuntu:18.04:LTS | exactimage | 0, 0.9.2-1build1, 1.0.1-1 |
| Ubuntu:22.04:LTS | exactimage | 1.0.2-8build2, 1.0.2-8, 0 |
…and 8 more
Exploit Intelligence
Timeline
- Dec 2, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Oct 29, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2015-8366 third-party-advisory
- https://ubuntu.com/security/notices/USN-3492-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2015-8366 third-party-advisory