CVE-2018-19565 PUBLISHED

A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

EPSS 0.30% · 52.8th percentile

Risk Scores

EPSS Score
0.30%
52.8th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSdcraw0, 9.28-3, 9.28-2
Ubuntu:25.10dcraw9.28-8, 0
Ubuntu:24.04:LTSdcraw9.28-3.1ubuntu1, 9.28-5ubuntu1, 0
Ubuntu:18.04:LTSdcraw9.27-1ubuntu1, 0
Ubuntu:20.04:LTSdcraw0, 9.28-2
Ubuntu:16.04:LTSdcraw0, 9.21-0.2

Timeline

References

Open in Interactive Console →