Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-2126

Опубликовано: 14 авг. 2013
Источник: debian

Описание

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librawfixed0.15.3-1package
librawno-dsawheezypackage
librawnot-affectedsqueezepackage
libkdcrawfixed24.12.0-1package
libkdcrawno-dsawheezypackage
darktablefixed1.2.1-2package
kdegraphicsremovedpackage
kdegraphicsnot-affectedsqueezepackage

Примечания

  • Not suitable for code injection, no security impact for an enduser application like Darktable

  • https://www.openwall.com/lists/oss-security/2013/05/28/3

  • https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6

  • Back in 2013, libkdcraw was fixed in 4:4.10.5-2 and later on removed and then

  • re-introduced in sid without the epoch, so now marking 24.12.0-1 as the first

  • upload to sid as the new fixed version, current libkdcraw uses the system-wide libraw

Связанные уязвимости

ubuntu
больше 12 лет назад

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

redhat
больше 12 лет назад

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

nvd
больше 12 лет назад

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

github
больше 3 лет назад

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

fstec
больше 12 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации