PT-2015-6336 · Dave Coffin+2 · Dcraw+2

Eduardo Castellanos

·

Published

2015-05-13

·

Updated

2025-04-28

·

CVE-2015-3885

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions dcraw versions 7.00 and earlier
Description The issue is related to an integer overflow in the ljpeg start function, which can be triggered by a crafted image. This overflow is associated with the len variable and can cause a denial of service (crash) due to a buffer overflow.
Recommendations For dcraw versions 7.00 and earlier, update to a version later than 7.00 to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2015-3885
DLA-228-1
DLA-243-1
DSA-3692-1
MGASA-2015-0222
MGASA-2015-0224
MGASA-2015-0225
MGASA-2015-0226
MGASA-2015-0230
MGASA-2016-0373
OPENSUSE-SU-2024:10478-1
OPENSUSE-SU-2024:10588-1
SUSE-SU-2017:2300-1
SUSE-SU-2017_2300-1
SUSE-SU-2025:1380-1
SUSE-SU-2025_1380-1
USN-3492-1

Affected Products

Suse
Ubuntu
Dcraw