Описание
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libraw | fixed | 0.15.4-1 | package | |
| libraw | no-dsa | wheezy | package | |
| libraw | no-dsa | squeeze | package | |
| libkdcraw | fixed | 24.12.0-1 | package | |
| libkdcraw | no-dsa | wheezy | package | |
| darktable | fixed | 1.2.2-2 | package | |
| darktable | fixed | 1.0.4-1+deb7u2 | wheezy | package |
Примечания
Back in 2013, libkdcraw was fixed in 4:4.10.5-2 and later on removed and then
re-introduced in sid without the epoch, so now marking 24.12.0-1 as the first
upload to sid as the new fixed version, current libkdcraw uses the system-wide libraw
EPSS
Связанные уязвимости
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS