Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8366

Опубликовано: 14 янв. 2020
Источник: debian

Описание

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librawfixed0.17.1-1package
librawfixed0.16.0-9+deb8u2jessiepackage
librawnot-affectedwheezypackage
librawnot-affectedsqueezepackage
dcrawfixed9.28-1package
dcrawno-dsastretchpackage
dcrawno-dsajessiepackage
dcrawnot-affectedwheezypackage
dcrawnot-affectedsqueezepackage
kodinot-affectedpackage
darktablefixed2.0.0-1package
darktablenot-affectedjessiepackage
darktablenot-affectedwheezypackage
darktablenot-affectedsqueezepackage
ufrawfixed0.20-4package
ufrawno-dsajessiepackage
ufrawnot-affectedwheezypackage
ufrawnot-affectedsqueezepackage
rawtherapeefixed4.2.1241-2package
rawtherapeefixed4.2-1+deb8u2jessiepackage
rawtherapeenot-affectedwheezypackage
rawtherapeenot-affectedsqueezepackage
exactimagefixed0.9.1-13package
exactimagefixed0.8.9-7+deb8u2jessiepackage
exactimagenot-affectedwheezypackage
exactimagenot-affectedsqueezepackage

Примечания

  • exactimage: smal_decode_segment inside dcraw.h not dcraw.c

  • Fixed by: https://github.com/LibRaw/LibRaw/commit/89d065424f09b788f443734d44857289489ca9e2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

redhat
около 10 лет назад

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

CVSS3: 9.8
nvd
около 6 лет назад

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

CVSS3: 9.8
github
больше 3 лет назад

Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.