CVE-2018-5813 PUBLISHED

An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.

EPSS 0.46% · 63.7th percentile

Risk Scores

EPSS Score
0.46%
63.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSrawtherapee0, 5.8-1, 5.7-1
Ubuntu:25.10kodi2:21.2+dfsg-4build2, 2:21.2+dfsg-4build1, 2:21.2+dfsg-4
Ubuntu:14.04:LTSlibraw0.15.4-1, 0.15.4-1ubuntu0.2, 0
Ubuntu:16.04:LTSexactimage0.9.1-8ubuntu1, 0.9.1-12ubuntu1, 0.9.1-12
Ubuntu:25.10exactimage1.2.1-2, 0
Ubuntu:16.04:LTSdcraw0, 9.21-0.2
Ubuntu:25.10darktable5.0.1-2, 5.0.1-0ubuntu2, 5.0.1-1
Ubuntu:25.10rawtherapee5.11-2build2, 0
Ubuntu:24.04:LTSdarktable4.4.2-1.1build1, 0, 4.4.2-1ubuntu1
Ubuntu:16.04:LTSufraw0, 0.20-3build1
Ubuntu:25.10dcraw0, 9.28-8
Ubuntu:16.04:LTSdarktable2.0.3-1, 2.0.0-1, 1.6.9-1
Ubuntu:22.04:LTSexactimage1.0.2-8, 1.0.2-8build3, 1.0.2-8build2
Ubuntu:22.04:LTSkodi2:19.3+dfsg1-1build2, 2:19.3+dfsg1-1, 2:19.1+dfsg2-2
Ubuntu:24.04:LTSexactimage1.0.2-11build4, 1.0.2-11build8, 1.0.2-11build9
Ubuntu:16.04:LTSlibraw0.17.1-1, 0.17.1-1ubuntu0.3, 0.17.1-1ubuntu0.2
Ubuntu:18.04:LTSrawtherapee0, 5.2-1, 5.3-1
Ubuntu:18.04:LTSkodi2:17.3+dfsg1-5build1, 2:17.3+dfsg1-5build2, 2:17.6+dfsg1-1
Ubuntu:20.04:LTSexactimage1.0.2-5ubuntu2, 0, 1.0.2-3
Ubuntu:24.04:LTSdcraw0, 9.28-3.1ubuntu1, 9.28-5ubuntu1

…and 15 more

Timeline

References

Open in Interactive Console →