The LibRaw raw image decoder <= 0.17 has multi vulnerability to cause memory errors,which may cause code execution or other problems.Problems has been fixed in 0.17.1(www.libraw.org/news/libraw-0-17-1).
Case CVE-2015-8366,Libraw smal_decode_segment function do not handle index carefully,which may cause index overflow.
Case CVE-2015-8367,Libraw phase_one_correct function do not handle memory object¡¯s initialization correctly,which may cause some other problems.
patches for this problem that changes the default is available(git-format-patch).
We suggest you take one of the following actions, in order of preference:
A - Upgrade LibRaw to the latest(www.libraw.org/download)
B - Apply the patch to your version and rebuild
- 2015/11/24 I discovered the memory error bug and reported to the email@example.com.
- 2015/11/25 The vendor response with the coordination and publish new release(www.libraw.org/news/libraw-0-17-1 <http://www.libraw.org/news/libraw-0-17-1>).
- 2015/11/26 Cve-id request to the firstname.lastname@example.org.
- 2015/11/27 Cve-id assigned,CVE-2015-8366 and CVE-2015-8367,Mailed Vendor.
- 2015/11/30 Publish to email@example.com.
ChenQin <firstname.lastname@example.org> of Topsec Security Team(www.topsec.com.cn)
Huakong Mansion, 1 East Shangdi Road, Haidian District, Beijing,100085 CN