CVE-2023-1729
Summary
| CVE | CVE-2023-1729 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-15 22:15:00 UTC |
| Updated | 2023-12-22 13:15:00 UTC |
| Description | A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5412-1 libraw |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 38 Update: mingw-LibRaw-0.21.1-3.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| LibRaw: Heap Buffer Overflow (GLSA 202312-08) — Gentoo security |
|
security.gentoo.org |
|
| There exists heap-buffer-overflow when using function raw2image_ex(int) · Issue #557 · LibRaw/LibRaw · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: mingw-LibRaw-0.21.1-3.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: mingw-LibRaw-0.20.2-9.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 2188240 – (CVE-2023-1729) CVE-2023-1729 LibRaw: a heap-buffer-overflow in raw2image_ex() |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] [DLA 3433-1] libraw security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 37 Update: mingw-LibRaw-0.20.2-9.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181806 Debian Security Update for libraw (DLA 3433-1)
- 181809 Debian Security Update for libraw (DSA 5412-1)
- 182863 Debian Security Update for libraw (CVE-2023-1729)
- 199394 Ubuntu Security Notification for LibRaw Vulnerabilities (USN-6137-1)
- 283961 Fedora Security Update for digikam (FEDORA-2023-573f6adf01)
- 283962 Fedora Security Update for digikam (FEDORA-2023-2c75a3bd51)
- 283969 Fedora Security Update for LibRaw (FEDORA-2023-fb8f800cb7)
- 283990 Fedora Security Update for mingw (FEDORA-2023-88c87f6191)
- 284141 Fedora Security Update for mingw (FEDORA-2023-b19f236bc7)
- 284144 Fedora Security Update for LibRaw (FEDORA-2023-659606fa84)
- 503196 Alpine Linux Security Update for libraw
- 506108 Alpine Linux Security Update for libraw
- 673825 EulerOS Security Update for libraw (EulerOS-SA-2023-3134)
- 710808 Gentoo Linux LibRaw Heap Buffer Overflow Vulnerability (GLSA 202312-08)
- 754015 SUSE Enterprise Linux Security Update for libraw (SUSE-SU-2023:2196-1)