Security update for libraw
This update for libraw fixes the following issues: Security issues fixed: - CVE-2017-13735: A floating point exception in kodak_radc_load_raw could be used by attackers to crash a libraw using application (bsc#1060321) - CVE-2017-14608: An out-of-bounds read in the kodak_65000_load_raw function could be used for crashing or information leak from the libraw library (bsc#1063798) - CVE-2017-16909: Fix heap-buffer overflow in the LibRaw::panasonic_load_raw() function (bsc#1072385).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libraw fixes the following issues: Security issues fixed: - CVE-2017-13735: A floating point exception in kodak_radc_load_raw could be used by attackers to crash a libraw using application (bsc#1060321) - CVE-2017-14608: An out-of-bounds read in the kodak_65000_load_raw function could be used for crashing or information leak from the libraw library (bsc#1063798) - CVE-2017-16909: Fix heap-buffer overflow in the LibRaw::panasonic_load_raw() function (bsc#1072385).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1060321
- https://bugzilla.suse.com/1063798
- https://bugzilla.suse.com/1072385
- https://www.suse.com/security/cve/CVE-2017-13735
- https://www.suse.com/security/cve/CVE-2017-14608
- https://www.suse.com/security/cve/CVE-2017-16909
- https://www.suse.com/support/update/announcement/2017/suse-su-20173392-1/