OSV-2023-1356

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/librawspeed/OSV-2023-1356.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-1356
Published
2023-12-25T00:10:36.482844Z
Modified
2023-12-25T00:10:36.483166Z
Summary
Heap-buffer-overflow in rawspeed::DngDecoder::parseWhiteBalance
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=65309

Crash type: Heap-buffer-overflow READ 4
Crash state:
rawspeed::DngDecoder::parseWhiteBalance
rawspeed::DngDecoder::decodeMetaDataInternal
rawspeed::RawDecoder::decodeMetaData
References

Affected packages

OSS-Fuzz / librawspeed

Package

Name
librawspeed
Purl
pkg:generic/librawspeed

Affected ranges

Type
GIT
Repo
https://github.com/darktable-org/rawspeed.git
Events

Affected versions

v3.*

v3.6

Ecosystem specific

{
    "severity": "MEDIUM"
}