CVE-2017-6886 (https://nvd.nist.gov/vuln/detail/CVE-2017-6886): An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory. References: http://www.securityfocus.com/bid/98605 https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251 https://secuniaresearch.flexerasoftware.com/advisories/75737/ https://secuniaresearch.flexerasoftware.com/secunia_research/2017-5/ CVE-2017-6887 (https://nvd.nist.gov/vuln/detail/CVE-2017-6887): A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs. References: http://www.securityfocus.com/bid/98592 https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251 https://secuniaresearch.flexerasoftware.com/advisories/75737/ https://secuniaresearch.flexerasoftware.com/secunia_research/2017-6/ @ Maintainer(s): Please state if the package is ready for stabilization for =media-libs/libraw-0.18.2.
ia64 stable
alpha stable
amd64/x86 stable
arm stable
sparc was dropped to exp. https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b5901d8f716555a1479f12313a2925fcadd177a9
ppc64 stable
ppc stable
hppa stable
GLSA Vote: No