LWN.net Logo

libraw: code execution

Package(s):libraw CVE #(s):CVE-2013-2126
Created:June 7, 2013 Updated:July 31, 2013
Description:

From the Secunia advisory:

Two vulnerabilities have been reported in LibRaw, which can be exploited by malicious people to potentially compromise an application using the library.

1) A double-free error exits when handling damaged full-color within Foveon and sRAW files.

2) An error during exposure correction can be exploited to cause a buffer overflow.

Successful exploitation may allow execution of arbitrary code.

Alerts:
Mageia MGASA-2013-0167 2013-06-06
Fedora FEDORA-2013-9773 2013-06-11
Fedora FEDORA-2013-9798 2013-06-11
Ubuntu USN-1884-1 2013-06-18
Ubuntu USN-1885-1 2013-06-18
openSUSE openSUSE-SU-2013:1083-1 2013-06-26
openSUSE openSUSE-SU-2013:1085-1 2013-06-26
openSUSE openSUSE-SU-2013:1168-1 2013-07-10
Mageia MGASA-2013-0223 2013-07-21
Mageia MGASA-2013-0219 2013-07-21
Fedora FEDORA-2013-13112 2013-07-24
Fedora FEDORA-2013-13038 2013-07-24
Fedora FEDORA-2013-13499 2013-07-30
Mageia MGASA-2013-0269 2013-09-01
Gentoo 201309-09 2013-09-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds