An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://github.com/LibRaw/LibRaw/blob/master/Changelog.txt | third party advisory |
https://secuniaresearch.flexerasoftware.com/advisories/83050/ | third party advisory permissions required |
https://usn.ubuntu.com/3838-1/ | third party advisory vendor advisory |
https://secuniaresearch.flexerasoftware.com/secunia_research/2018-13/ | third party advisory |
https://github.com/LibRaw/LibRaw/commit/e47384546b43d0fd536e933249047bc397a4d88b | third party advisory patch |