An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
[
{
"source": "https://github.com/libraw/libraw/commit/e47384546b43d0fd536e933249047bc397a4d88b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"138481034920068687057640270736735149783",
"155008637328667895771217093114123597413",
"202468380364842969293143948639227716452",
"43362345418300741757744580791995773669",
"93498740150145970412707948942946017657",
"43849796945480050784384972864088438034",
"69979759779499482055485378711069337766",
"81314346554430816809408695689807658024",
"326138784518238356426912359781180545145"
]
},
"target": {
"file": "internal/dcraw_common.cpp"
},
"id": "CVE-2018-5813-2f06c7a3"
},
{
"source": "https://github.com/libraw/libraw/commit/e47384546b43d0fd536e933249047bc397a4d88b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"138481034920068687057640270736735149783",
"155008637328667895771217093114123597413",
"202468380364842969293143948639227716452",
"43362345418300741757744580791995773669",
"93498740150145970412707948942946017657",
"43849796945480050784384972864088438034",
"69979759779499482055485378711069337766",
"81314346554430816809408695689807658024",
"326138784518238356426912359781180545145"
]
},
"target": {
"file": "dcraw/dcraw.c"
},
"id": "CVE-2018-5813-a26917b4"
},
{
"source": "https://github.com/libraw/libraw/commit/e47384546b43d0fd536e933249047bc397a4d88b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "336648434298068837655732362148006286611",
"length": 3854.0
},
"target": {
"function": "parse_minolta",
"file": "internal/dcraw_common.cpp"
},
"id": "CVE-2018-5813-a456f537"
},
{
"source": "https://github.com/libraw/libraw/commit/e47384546b43d0fd536e933249047bc397a4d88b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "336648434298068837655732362148006286611",
"length": 3854.0
},
"target": {
"function": "parse_minolta",
"file": "dcraw/dcraw.c"
},
"id": "CVE-2018-5813-df5e2481"
}
]