Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1380-1

Опубликовано: 28 апр. 2025
Источник: suse-cvrf

Описание

Security update for libraw

This update for libraw fixes the following issues:

  • CVE-2025-43962: Fixed out-of-bounds read when tag 0x412 processing in phase_one_correct function (bsc#1241585)
  • CVE-2025-43964: Fixed tag 0x412 processing in phase_one_correct does not enforce minimum w0 and w1 values (bsc#1241584)

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libraw-devel-0.15.4-45.1
libraw-devel-static-0.15.4-45.1

Описание

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-0.15.4-45.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-static-0.15.4-45.1

Ссылки

Описание

The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-0.15.4-45.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-static-0.15.4-45.1

Ссылки

Описание

In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-0.15.4-45.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-static-0.15.4-45.1

Ссылки

Описание

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-0.15.4-45.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libraw-devel-static-0.15.4-45.1

Ссылки