CVE-2018-19655 PUBLISHED

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

EPSS 0.69% · 71.6th percentile

Risk Scores

EPSS Score
0.69%
71.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSufraw0.22-2, 0.22-3, 0
Ubuntu:16.04:LTSufraw0, 0.20-3build1
Ubuntu:16.04:LTSdcraw0, 9.21-0.2
Ubuntu:22.04:LTSdcraw0
Ubuntu:20.04:LTSdcraw0
Ubuntu:18.04:LTSdcraw0, 9.27-1ubuntu1

Timeline

References

Open in Interactive Console →