
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-1729 is a vulnerability discovered in LibRaw, a library for reading RAW files obtained from digital photo cameras. The vulnerability was identified as a heap-buffer-overflow in the raw2image_ex() function. This security flaw was reported on January 14, 2023, and affects various versions of LibRaw (LibRaw Issue, NVD).
The vulnerability is characterized by a heap-buffer-overflow condition in the raw2image_ex() function when processing maliciously crafted files. The issue occurs during memory operations, specifically in a WRITE operation of size 2224 bytes, which could lead to buffer overflow. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium), with attack vector being Network, attack complexity Low, and requiring user interaction (Ubuntu Security).
When exploited, this vulnerability can lead to application crashes when processing maliciously crafted files. The impact primarily affects the availability of applications using the LibRaw library, with no reported impacts on confidentiality or integrity (NVD, Debian Security).
The vulnerability has been fixed in multiple versions across different distributions. Fixes have been implemented through commits 9ab70f6dca19229cb5caad7cc31af4e7501bac93 and 477e0719ffc07190c89b4f3d12d51b1292e75828 in the LibRaw repository. Various distributions have released security updates, including Debian (version 0.20.2-1+deb11u1), Ubuntu, and Fedora (Debian Security, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."