ZeroHour

CVE-2018-19566

CVSS 3.0
7.1 high
EPSS
1%p63
Published
()
Modified
Description

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

Vendors
dcraw project
Products
dcraw
Weakness
CWE-125
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.