LWN.net Logo

LibRaw: denial of service

Package(s):LibRaw CVE #(s):CVE-2013-1439
Created:September 10, 2013 Updated:September 11, 2013
Description: From the Fedora advisory:

Specially crafted photo files may trigger a series of conditions in which a null pointer is dereferenced leading to denial of service in applications using the library. These three vulnerabilities are in/related to the 'faster LJPEG decoder', which upstream states was introduced in LibRaw 0.13 and support for which is going to be dropped in 0.16.

Alerts:
Fedora FEDORA-2013-15562 2013-09-09
Fedora FEDORA-2013-15576 2013-09-09
Gentoo 201309-09 2013-09-15
Ubuntu USN-1964-1 2013-09-23
Ubuntu USN-1978-1 2013-09-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds