Source: libraw Version: 0.18.8-2 Severity: important Tags: patch security upstream Forwarded: https://github.com/LibRaw/LibRaw/issues/144
Hi, The following vulnerability was published for libraw. CVE-2018-10529[0]: | An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds | read affecting the X3F property table list implementation in | libraw_x3f.cpp and libraw_cxx.cpp. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2018-10529 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10529 [1] https://github.com/LibRaw/LibRaw/issues/144 [2] https://github.com/LibRaw/LibRaw/commit/f0c505a3e5d47989a5f69be2d0d4f250af6b1a6c Please adjust the affected versions in the BTS as needed. Regards, Salvatore