Dave Coffin · Dcraw · CVE-2015-3885
**Name of the Vulnerable Software and Affected Versions**
dcraw versions 7.00 and earlier
**Description**
The issue is related to an integer overflow in the `ljpeg start` function, which can be triggered by a crafted image. This overflow is associated with the `len` variable and can cause a denial of service (crash) due to a buffer overflow.
**Recommendations**
For dcraw versions 7.00 and earlier, update to a version later than 7.00 to resolve the issue.