Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3885

Опубликовано: 19 мая 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dcraw_project:dcraw:*:*:*:*:*:*:*:*
Версия до 7.00 (включая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03564
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

redhat
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

debian
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier ...

github
больше 3 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

suse-cvrf
10 месяцев назад

Security update for libraw

EPSS

Процентиль: 87%
0.03564
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-189