Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3885

Опубликовано: 19 мая 2015
Источник: debian
EPSS Низкий

Описание

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dcrawfixed9.26-1package
dcrawno-dsajessiepackage
dcrawno-dsawheezypackage
dcrawno-dsasqueezepackage
ufrawfixed0.20-3package
ufrawfixed0.20-2+deb8u1jessiepackage
ufrawno-dsawheezypackage
ufrawno-dsasqueezepackage
librawfixed0.16.2-1package
librawfixed0.16.0-9+deb8u1jessiepackage
librawfixed0.14.6-2+deb7u1wheezypackage
librawno-dsasqueezepackage
rawtherapeefixed4.2-2package
rawtherapeefixed4.2-1+deb8u1jessiepackage
rawtherapeefixed4.0.9-4+deb7u1wheezypackage
rawtherapeeno-dsasqueezepackage
rawstudioremovedpackage
rawstudiono-dsawheezypackage
rawstudiono-dsasqueezepackage
xbmcfixed2:13.2+dfsg1-5package
xbmcno-dsajessiepackage
xbmcno-dsawheezypackage
kodifixed16.0+dfsg1-1package
exactimagefixed0.9.1-5package
exactimagefixed0.8.9-7+deb8u1jessiepackage
exactimagefixed0.8.5-5+deb7u4wheezypackage
exactimageno-dsasqueezepackage
freeimagefixed3.15.4-6package
freeimageno-dsawheezypackage
freeimageno-dsasqueezepackage
darktablefixed1.6.7-1package
darktablefixed1.4.2-1+deb8u1jessiepackage
darktableno-dsawheezypackage

Примечания

  • http://www.ocert.org/advisories/ocert-2015-006.html

  • https://codesearch.debian.net/results/int%20CLASS%20ljpeg_start

  • Starting with 2:13.2+dfsg1-5 xbmc is a transitional package

EPSS

Процентиль: 87%
0.03564
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

redhat
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

nvd
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

github
больше 3 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

suse-cvrf
10 месяцев назад

Security update for libraw

EPSS

Процентиль: 87%
0.03564
Низкий