PT-2013-1243 · Dave Coffin · Libraw+1

Published

2013-08-30

·

Updated

2016-11-28

·

CVE-2013-1438

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dcraw versions 0.8.x through 0.8.9 libraw versions prior to 0.15.4
Description The issue allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a divide-by-zero, infinite loop, or NULL pointer dereference. Multiple vulnerabilities in the libraw package can lead to violations of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely.
Recommendations For dcraw versions 0.8.x through 0.8.9, update to a version later than 0.8.9 to resolve the issue. For libraw versions prior to 0.15.4, update to version 0.15.4 or later to fix the vulnerabilities.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09729
CVE-2013-1438
DSA-2748-1
MGASA-2013-0301
MGASA-2013-0385
MGASA-2014-0011
MGASA-2014-0050
MGASA-2014-0071
MGASA-2014-0081
USN-1964-1
USN-1978-1

Affected Products

Dcraw
Libraw