Описание
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libraw | fixed | 0.15.4-1 | package | |
| libraw | no-dsa | wheezy | package | |
| libraw | no-dsa | squeeze | package | |
| libkdcraw | fixed | 24.12.0-1 | package | |
| libkdcraw | no-dsa | wheezy | package | |
| darktable | fixed | 1.2.2-2 | package | |
| darktable | fixed | 1.0.4-1+deb7u2 | wheezy | package |
| dcraw | fixed | 9.28-1 | package | |
| ufraw | fixed | 0.19.2-2 | package | |
| ufraw | no-dsa | wheezy | package | |
| ufraw | no-dsa | squeeze | package | |
| xbmc | fixed | 2:13.2+dfsg1-5 | package | |
| exactimage | fixed | 0.8.9-1 | package | |
| rawstudio | removed | package | ||
| rawtherapee | not-affected | package |
Примечания
Starting with 2:13.2+dfsg1-5 xbmc is a transitional package
Back in 2013, libkdcraw was fixed in 4:4.10.5-2 and later on removed and then
re-introduced in sid without the epoch, so now marking 24.12.0-1 as the first
upload to sid as the new fixed version, current libkdcraw uses the system-wide libraw
EPSS
Связанные уязвимости
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS