|
|
| |
|
| |
libraw: code execution
| Package(s): | libraw |
CVE #(s): | CVE-2013-2126
|
| Created: | June 7, 2013 |
Updated: | July 31, 2013 |
| Description: |
From the Secunia advisory:
Two vulnerabilities have been reported in LibRaw, which can be exploited by malicious people to potentially compromise an application using the library.
1) A double-free error exits when handling damaged full-color within Foveon and sRAW files.
2) An error during exposure correction can be exploited to cause a buffer overflow.
Successful exploitation may allow execution of arbitrary code. |
| Alerts: |
|
( Log in to post comments)
|
|
|