Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3885

Опубликовано: 11 мая 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

A flaw was discovered in the way dcraw processed Raw images. An attacker could use this flaw to cause dcraw to crash by tricking a user into processing a specially crafted Raw image file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dcrawWill not fix
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Linux 6dcrawWill not fix
Red Hat Enterprise Linux 6netpbmWill not fix
Red Hat Enterprise Linux 7dcrawWill not fix
Red Hat Enterprise Linux 7libkdcrawWill not fix
Red Hat Enterprise Linux 7LibRawWill not fix
Red Hat Enterprise Linux 7netpbmWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-190->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1221249dcraw: input sanitization flaw leading to buffer overflow

EPSS

Процентиль: 87%
0.03564
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

nvd
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

debian
больше 10 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier ...

github
больше 3 лет назад

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

suse-cvrf
10 месяцев назад

Security update for libraw

EPSS

Процентиль: 87%
0.03564
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2015-3885