CESA-2018:3065 -- centos 7 libkdcrawID: oval:org.secpod.oval:def:205099 | Date: (C)2021-01-19 (M)2023-06-01 |
Class: PATCH | Family: unix |
Libkdcraw is a C++ interface around the LibRaw library used to decode the RAW picture files. Security Fix: * LibRaw: Stack-based buffer overflow in quicktake_100_load_raw function in internal/dcraw_common.cpp * LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp * LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp * LibRaw: Out-of-bounds read in kodak_radc_load_raw function internal/dcraw_common.cpp * LibRaw: NULL pointer dereference in leaf_hdr_load_raw function in internal/dcraw_common.cpp For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.