{"schema_version":"1.7.5","id":"CVE-2017-6886","published":"2017-05-16T16:29:00.220Z","modified":"2026-07-08T16:53:22.774838Z","related":["SUSE-SU-2017:2300-1","openSUSE-SU-2024:10980-1"],"details":"An error within the \"parse_tiff_ifd()\" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libraw/libraw","events":[{"introduced":"0"},{"last_affected":"f4e199a14566f511d1d3d5ad839fef5f4eb906ff"},{"fixed":"d7c3d2cb460be10a3ea7b32e9443a83c243b2251"}],"database_specific":{"cpe":"cpe:2.3:a:libraw:libraw:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.18.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.18.1","0.18.0","0.17.0","0.16.0","0.15.0","0.14.6","0.14.5","0.14.4","0.14.3","0.14.2","0.14.1","0.14.0","0.13.6","0.13.5","0.13.4","0.13.3","0.13.2","0.13.1","0.13.0","0.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6886.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["330483907310885657851638621784502241594","98297358945102826810003107118541587412","13538086109817097211732976274570932189","140070819662391359961719678473990694994","40273550911795736478718628460633290601","242256858762420658105829523284864040693","157899024790148287550800316389812572087","222565264877867960609186580260913843692","40686553183327440519215951091695956570","230815494714399470105896906696210971826","201572566780869375995244731736247661949","145021184640497432325317046080675481440"],"threshold":0.9},"id":"CVE-2017-6886-07f0dd62","signature_type":"Line","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251","target":{"file":"internal/dcraw_common.cpp"}},{"deprecated":false,"digest":{"function_hash":"223952729540945911801236471202363549232","length":836},"id":"CVE-2017-6886-345db300","signature_type":"Function","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251","target":{"file":"dcraw/dcraw.c","function":"parse_jpeg"}},{"deprecated":false,"digest":{"line_hashes":["330483907310885657851638621784502241594","98297358945102826810003107118541587412","13538086109817097211732976274570932189","140070819662391359961719678473990694994","40273550911795736478718628460633290601","242256858762420658105829523284864040693","157899024790148287550800316389812572087","222565264877867960609186580260913843692","40686553183327440519215951091695956570","230815494714399470105896906696210971826","201572566780869375995244731736247661949","145021184640497432325317046080675481440"],"threshold":0.9},"id":"CVE-2017-6886-3bf7c58f","signature_type":"Line","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251","target":{"file":"dcraw/dcraw.c"}},{"deprecated":false,"digest":{"function_hash":"270558865765251762118260754155532321526","length":31716},"id":"CVE-2017-6886-62aafd68","signature_type":"Function","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251","target":{"file":"dcraw/dcraw.c","function":"parse_tiff_ifd"}},{"deprecated":false,"digest":{"function_hash":"223952729540945911801236471202363549232","length":836},"id":"CVE-2017-6886-70b33685","signature_type":"Function","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251","target":{"file":"internal/dcraw_common.cpp","function":"parse_jpeg"}},{"deprecated":false,"digest":{"function_hash":"270558865765251762118260754155532321526","length":31716},"id":"CVE-2017-6886-78c14c72","signature_type":"Function","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251","target":{"file":"internal/dcraw_common.cpp","function":"parse_tiff_ifd"}}],"vanir_signatures_modified":"2026-07-08T16:53:22Z"}}],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3950"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98605"},{"type":"REPORT","url":"https://secuniaresearch.flexerasoftware.com/advisories/75737/"},{"type":"REPORT","url":"https://secuniaresearch.flexerasoftware.com/secunia_research/2017-5/"},{"type":"FIX","url":"https://github.com/LibRaw/LibRaw/commit/d7c3d2cb460be10a3ea7b32e9443a83c243b2251"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}