The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/134573/LibRaw-0.17-Overflow.html | third party advisory vdb entry |
http://www.libraw.org/news/libraw-0-17-1 | vendor advisory |
http://seclists.org/fulldisclosure/2015/Nov/108 | third party advisory mailing list |