CVE-2018-19566 PUBLISHED

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

EPSS 0.20% · 42.1th percentile

Risk Scores

EPSS Score
0.20%
42.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSdcraw0, 9.21-0.2
Ubuntu:18.04:LTSdcraw0, 9.27-1ubuntu1
Ubuntu:25.10dcraw9.28-8, 0
Ubuntu:22.04:LTSdcraw0, 9.28-2, 9.28-3
Ubuntu:24.04:LTSdcraw0, 9.28-3, 9.28-3.1ubuntu1
Ubuntu:20.04:LTSdcraw0, 9.28-2

Timeline

References

Open in Interactive Console →