{"schema_version":"1.7.5","id":"CVE-2018-10528","published":"2018-04-29T03:29:00.310Z","modified":"2026-07-08T14:59:13.477351Z","related":["openSUSE-SU-2024:10980-1"],"details":"An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libraw/libraw","events":[{"introduced":"87144aa9bb7325b09965b183fa58f957a9a4e4fd"},{"last_affected":"87144aa9bb7325b09965b183fa58f957a9a4e4fd"},{"fixed":"efd8cfabb93fd0396266a7607069901657c082e3"}],"database_specific":{"cpe":"cpe:2.3:a:libraw:libraw:0.18.9:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.18.9"},{"last_affected":"0.18.9"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.18.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10528.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"252336533857689643885418014743752931165","length":204},"id":"CVE-2018-10528-109dd588","signature_type":"Function","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/efd8cfabb93fd0396266a7607069901657c082e3","target":{"file":"src/libraw_cxx.cpp","function":"utf2char"}},{"deprecated":false,"digest":{"function_hash":"67370514212402055096699002759909826972","length":5429},"id":"CVE-2018-10528-4aaec1c0","signature_type":"Function","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/efd8cfabb93fd0396266a7607069901657c082e3","target":{"file":"src/libraw_cxx.cpp","function":"LibRaw::parse_x3f"}},{"deprecated":false,"digest":{"line_hashes":["154890432160439294006430619712520052245","138986028489103972689014037731769997393","103099074472438459681567086872941143178","12455845976305421023743675851513522855","8536276503149737419853247581135011742","334169772272254958991513935062430038027","55023915806102155922583115239082328038","253565321359962370225994169901000094482","299264130701775429199092333659680755680","95466403734629571529776646325624195481","248727732483071687414452209806770728484","259059947503145621007055758932539717903","268489085269868056506827985562763529183","88460514338855426367820464401841263514","307498728798500769076404506513026651202","297536214377360789117078215482225662086","54328197893581282840175486322468253411","17621035509924748660311649333895136878"],"threshold":0.9},"id":"CVE-2018-10528-731e6467","signature_type":"Line","signature_version":"v1","source":"https://github.com/libraw/libraw/commit/efd8cfabb93fd0396266a7607069901657c082e3","target":{"file":"src/libraw_cxx.cpp"}}],"vanir_signatures_modified":"2026-07-08T14:59:13Z"}}],"references":[{"type":"ADVISORY","url":"https://github.com/LibRaw/LibRaw/issues/144"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3639-1/"},{"type":"FIX","url":"https://github.com/LibRaw/LibRaw/commit/efd8cfabb93fd0396266a7607069901657c082e3"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"],"extracted_events":[{"introduced":"16.04"},{"last_affected":"16.04"},{"introduced":"17.10"},{"last_affected":"17.10"},{"introduced":"18.04"},{"last_affected":"18.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}