In LibRaw before 0.21.4, phase_one_correct in decoders...
Low severity
Unreviewed
Published
Apr 21, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Apr 21, 2025
Published to the GitHub Advisory Database
Apr 21, 2025
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
References