{"schema_version":"1.7.3","id":"SUSE-SU-2022:1749-1","published":"2022-05-19T13:24:56Z","modified":"2026-02-04T03:48:46.791697Z","related":["CVE-2017-13735","CVE-2017-14608","CVE-2018-19565","CVE-2018-19566","CVE-2018-19567","CVE-2018-19568","CVE-2018-19655","CVE-2018-5801","CVE-2018-5805","CVE-2018-5806","CVE-2021-3624"],"upstream":["CVE-2017-13735","CVE-2017-14608","CVE-2018-19565","CVE-2018-19566","CVE-2018-19567","CVE-2018-19568","CVE-2018-19655","CVE-2018-5801","CVE-2018-5805","CVE-2018-5806","CVE-2021-3624"],"summary":"Security update for dcraw","details":"This update for dcraw fixes the following issues:\n\n- CVE-2017-13735: Fixed a denial of service issue due to a floating point\n  exception (bsc#1056170).\n- CVE-2017-14608: Fixed an invalid memory access that could lead to information\n  disclosure or denial of service (bsc#1063798).\n- CVE-2018-19655: Fixed a buffer overflow that could lead to an application\n  crash (bsc#1117896).\n- CVE-2018-5801: Fixed an invalid memory access that could lead to denial of\n  service (bsc#1084690).\n- CVE-2018-5805: Fixed a buffer overflow that could lead to an application crash\n  (bsc#1097973).\n- CVE-2018-5806: Fixed an invalid memory access that could lead to denial of\n  service (bsc#1097974).\n- CVE-2018-19565: Fixed an invalid memory access that could lead to information\n  disclosure or denial of service (bsc#1117622).\n- CVE-2018-19566: Fixed an invalid memory access that could lead to information\n  disclosure or denial of service (bsc#1117517).\n- CVE-2018-19567: Fixed a denial of service issue due to a floating point\n  exception (bsc#1117512).\n- CVE-2018-19568: Fixed a denial of service issue due to a floating point\n  exception (bsc#1117436).\n- CVE-2021-3624: Fixed a buffer overflow that could lead to code execution or\n  denial of service (bsc#1189642).\n\nNon-security fixes:\n\n- Updated to version 9.28.0.\n","affected":[{"package":{"name":"dcraw","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/dcraw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.28.0-3.3.1"}]}],"ecosystem_specific":{"binaries":[{"dcraw":"9.28.0-3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1749-1.json"}},{"package":{"name":"dcraw","ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP5","purl":"pkg:rpm/suse/dcraw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.28.0-3.3.1"}]}],"ecosystem_specific":{"binaries":[{"dcraw":"9.28.0-3.3.1","dcraw-lang":"9.28.0-3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1749-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20221749-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1056170"},{"type":"REPORT","url":"https://bugzilla.suse.com/1063798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1084690"},{"type":"REPORT","url":"https://bugzilla.suse.com/1097973"},{"type":"REPORT","url":"https://bugzilla.suse.com/1097974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117512"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117622"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117896"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189642"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13735"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-14608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19565"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19566"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19567"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19568"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19655"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5801"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5805"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3624"}]}