In LibRaw through 0.18.4, an out of bounds read flaw related to kodak65000loadraw has been reported in dcraw/dcraw.c and internal/dcrawcommon.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
{ "vanir_signatures": [ { "digest": { "line_hashes": [ "202157822897561779189183472516495530908", "144687929659205114131421584750958499196", "334708782772715860409840809220348812915", "209885300085744681948805856641535568215", "11230180545788369180989943269865665904" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2017-14608-1981bad3", "signature_version": "v1", "target": { "file": "internal/dcraw_common.cpp" }, "source": "https://github.com/libraw/libraw/commit/d13e8f6d1e987b7491182040a188c16a395f1d21", "deprecated": false }, { "digest": { "line_hashes": [ "202157822897561779189183472516495530908", "144687929659205114131421584750958499196", "334708782772715860409840809220348812915", "209885300085744681948805856641535568215", "11230180545788369180989943269865665904" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2017-14608-376f19eb", "signature_version": "v1", "target": { "file": "dcraw/dcraw.c" }, "source": "https://github.com/libraw/libraw/commit/d13e8f6d1e987b7491182040a188c16a395f1d21", "deprecated": false }, { "digest": { "length": 496.0, "function_hash": "138374478490586344001064023637424054982" }, "signature_type": "Function", "id": "CVE-2017-14608-4c34d868", "signature_version": "v1", "target": { "function": "kodak_65000_load_raw", "file": "dcraw/dcraw.c" }, "source": "https://github.com/libraw/libraw/commit/d13e8f6d1e987b7491182040a188c16a395f1d21", "deprecated": false }, { "digest": { "length": 496.0, "function_hash": "138374478490586344001064023637424054982" }, "signature_type": "Function", "id": "CVE-2017-14608-b1f334a2", "signature_version": "v1", "target": { "function": "kodak_65000_load_raw", "file": "internal/dcraw_common.cpp" }, "source": "https://github.com/libraw/libraw/commit/d13e8f6d1e987b7491182040a188c16a395f1d21", "deprecated": false } ] }