Vulnerability Details CVE-2018-19566
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.6%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 5.8
Products affected by CVE-2018-19566
-
cpe:2.3:a:dcraw_project:dcraw:7.00
-
cpe:2.3:a:dcraw_project:dcraw:9.28