Oval Definition:oval:com.redhat.rhsa:def:20183065
Revision Date:2018-10-30Version:637
Title:RHSA-2018:3065: libkdcraw security update (Moderate)
Description:Libkdcraw is a C++ interface around the LibRaw library used to decode the RAW picture files.

Security Fix(es):

  • LibRaw: Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5805)

  • LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp (CVE-2018-5800)

  • LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp (CVE-2018-5801)

  • LibRaw: Out-of-bounds read in kodak_radc_load_raw function internal/dcraw_common.cpp (CVE-2018-5802)

  • LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5806)

    For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-5800
    CVE-2018-5801
    CVE-2018-5802
    CVE-2018-5805
    CVE-2018-5806
    RHSA-2018:3065
    RHSA-2018:3065-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • libkdcraw is earlier than 0:4.10.5-5.el7
  • AND libkdcraw is signed with Red Hat redhatrelease2 key
  • libkdcraw-devel is earlier than 0:4.10.5-5.el7
  • AND libkdcraw-devel is signed with Red Hat redhatrelease2 key
  • BACK