LibRaw: multiple denial of service flaws
Published Jan 19, 2014
4.3
MEDIUMCVSS 2.0
EPSS 2.06%
Description
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Affected products
No data.
- 0.8.0
- 0.8.1
- 0.8.2
- 0.8.3
- 0.8.4
- 0.8.5
- 0.8.6
- 0.8.7
- 0.8.8
- 0.8.9
No data.
Red Hat Enterprise Linux 5
dcraw
Will not fix
Red Hat Enterprise Linux 6
dcraw
Will not fix
Red Hat Enterprise Linux 7
LibRaw
Will not fix
Red Hat Enterprise Linux 7
dcraw
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | dcraw | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | dcraw | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | LibRaw | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | dcraw | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
No CWE recorded.
References (8)
- http://www.debian.org/security/2013/dsa-2748 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2013/08/29/3 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/62060 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-1438 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1002714 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-1438
- https://www.cve.org/CVERecord?id=CVE-2013-1438
| Link | Providers | Tags |
|---|---|---|
| http://www.debian.org/security/2013/dsa-2748 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.openwall.com/lists/oss-security/2013/08/29/3 | mailing-listx_refsource_MLIST | |
| http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/62060 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2013-1438 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1002714 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-1438 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-1438 |
Change history (0)
No recorded changes yet.