CVE-2025-43964
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 21, 2025
Updated: May 8, 2025
CWE ID 1284
Summary
CVE-2025-43964 is a vulnerability affecting LibRaw before version 0.21.4. This issue lies in the 'phase_one_correct' function within 'decoders/load_mfbacks.cpp'. The flaw permits incorrect processing of tag 0x412, specifically the minimum values of w0 and w1 are not enforced. This vulnerability could potentially lead to unintended behavior or even data corruption within the affected software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibRaw
Affected Vendors
- Libraw