Bug 1091345 (CVE-2018-10528)

Summary: VUL-0: CVE-2018-10528: libraw: There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp.
Product: [openSUSE] openSUSE Distribution Reporter: Karol Babioch <karol>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium    
Version: Leap 42.3   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/205018/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Karol Babioch 2018-04-30 08:49:26 UTC
CVE-2018-10528

An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow
in the utf2char function in libraw_cxx.cpp.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10528
https://github.com/LibRaw/LibRaw/issues/144
https://github.com/LibRaw/LibRaw/commit/895529fc2f2eb8bc633edd6b04b5b237eb4db564
Comment 2 Petr Gajdos 2018-04-30 09:53:12 UTC
Submitted to Tumbleweed and sle15.
Comment 3 Swamp Workflow Management 2018-04-30 10:20:05 UTC
This is an autogenerated message for OBS integration:
This bug (1091345) was mentioned in
https://build.opensuse.org/request/show/602481 Factory / libraw
Comment 5 Andreas Stieger 2018-04-30 11:09:14 UTC
openSUSE:Leap:42.3:Update/libraw has 0.17.1
Please submit a maintenance update there.
Comment 6 Petr Gajdos 2018-04-30 12:05:13 UTC
Done.
Comment 7 Swamp Workflow Management 2018-04-30 12:30:05 UTC
This is an autogenerated message for OBS integration:
This bug (1091345) was mentioned in
https://build.opensuse.org/request/show/602522 42.3 / libraw
Comment 8 Swamp Workflow Management 2018-05-03 10:09:21 UTC
openSUSE-SU-2018:1138-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1091345,1091346
CVE References: CVE-2018-10528,CVE-2018-10529
Sources used:
openSUSE Leap 42.3 (src):    libraw-0.17.1-20.1
Comment 9 Marcus Meissner 2018-06-13 15:49:08 UTC
released