CVE-2018-19655

UnknownEPSS 2.85%

Last modified

CVE-2018-19655 is a vulnerability of currently unknown severity. A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.. EPSS estimates a 2.85% chance of exploitation in the next 30 days.

Description

A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

Metrics

EPSS Probability
2.85%

84.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Dcraw ProjectDcraw<= 9.28
SuseSuse Linux Enterprise Desktop12Sp3
SuseSuse Linux Enterprise Server11Sp4
SuseSuse Linux Enterprise Server12Sp3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-19655?
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
How severe is CVE-2018-19655?
Severity scoring for CVE-2018-19655 is pending analysis. The EPSS model estimates a 2.85% probability of exploitation in the next 30 days.
How do I fix CVE-2018-19655?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-19655?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST