RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.
[
{
"source": "https://github.com/darktable-org/rawspeed/commit/dbe7591e54bad5e6430d38be6bed051582da76b9",
"id": "CVE-2018-25017-05742477",
"deprecated": false,
"target": {
"file": "src/librawspeed/common/TableLookUp.cpp"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"270971799370473575291749135196874086337",
"225561087439078754092139683906145410986",
"104725271343841795700519290889740867650",
"273426505611582158008056161110160814520"
]
}
},
{
"source": "https://github.com/darktable-org/rawspeed/commit/dbe7591e54bad5e6430d38be6bed051582da76b9",
"id": "CVE-2018-25017-56d2bdc3",
"deprecated": false,
"target": {
"function": "TableLookUp::setTable",
"file": "src/librawspeed/common/TableLookUp.cpp"
},
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 909.0,
"function_hash": "12198607757596020264529136127271702942"
}
}
]