CVE-2018-5802 is an out-of-bounds read vulnerability in the "kodak_radc_load_raw()" function of LibRaw versions prior to 0.18.7, affecting products like Canonical, Debian, and Red Hat. This high-severity flaw (CVSS 8.8) can be triggered remotely with low attack complexity, potentially leading to a denial-of-service condition (crash) and compromise of confidentiality and integrity. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it's not on CISA's KEV catalog, its high FAUCET Risk Score of 70/100 warrants attention. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.18.7CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.