Security update for libraw
This update for libraw fixes the following issues: Security issues fixed: - CVE-2018-5800: Fixed heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function (bsc#1084691). - CVE-2018-5801: Fixed NULL pointer dereference in LibRaw::unpack function (bsc#1084690). - CVE-2018-5802: Fixed out-of-bounds read in kodak_radc_load_raw function (bsc#1084688). - CVE-2018-5813: Fixed infinite loop in the parse_minolta function (bsc#1103200) - CVE-2018-5810: Fixed a heap-based buffer overflow in rollei_load_raw (bsc#1103353)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libraw fixes the following issues: Security issues fixed: - CVE-2018-5800: Fixed heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function (bsc#1084691). - CVE-2018-5801: Fixed NULL pointer dereference in LibRaw::unpack function (bsc#1084690). - CVE-2018-5802: Fixed out-of-bounds read in kodak_radc_load_raw function (bsc#1084688). - CVE-2018-5813: Fixed infinite loop in the parse_minolta function (bsc#1103200) - CVE-2018-5810: Fixed a heap-based buffer overflow in rollei_load_raw (bsc#1103353)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1084688
- https://bugzilla.suse.com/1084690
- https://bugzilla.suse.com/1084691
- https://bugzilla.suse.com/1103200
- https://bugzilla.suse.com/1103353
- https://www.suse.com/security/cve/CVE-2018-5800
- https://www.suse.com/security/cve/CVE-2018-5801
- https://www.suse.com/security/cve/CVE-2018-5802
- https://www.suse.com/security/cve/CVE-2018-5810
- https://www.suse.com/security/cve/CVE-2018-5813
- https://www.suse.com/support/update/announcement/2018/suse-su-20183343-1/