CVE-2013-1439

The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
debianCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
librawlibraw
0.13.0
librawlibraw
0.13.1
librawlibraw
0.13.2
librawlibraw
0.13.3
librawlibraw
0.13.4
librawlibraw
0.13.5
librawlibraw
0.13.6
librawlibraw
0.13.7
librawlibraw
0.13.8
librawlibraw
0.14.0
librawlibraw
0.14.1
librawlibraw
0.14.2
librawlibraw
0.14.3
librawlibraw
0.14.4
librawlibraw
0.14.5
librawlibraw
0.14.6
librawlibraw
0.14.7
librawlibraw
0.15.0
librawlibraw
0.15.1
librawlibraw
0.15.2
librawlibraw
0.15.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
darktable
bullseye
3.4.1-5
fixed
wheezy
no-dsa
squeeze
no-dsa
bookworm
4.2.1-4
fixed
sid
4.8.1-2
fixed
trixie
4.8.1-2
fixed
libraw
bullseye (security)
0.20.2-1+deb11u1
fixed
bullseye
0.20.2-1+deb11u1
fixed
wheezy
no-dsa
squeeze
no-dsa
bookworm
0.20.2-2.1
fixed
sid
0.21.3-1
fixed
trixie
0.21.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
darktable
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
yakkety
ignored
xenial
not-affected
wily
ignored
vivid
ignored
utopic
ignored
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
dne
libkdcraw
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
not-affected
yakkety
ignored
xenial
not-affected
wily
ignored
vivid
ignored
utopic
ignored
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
Fixed 4:4.8.5-0ubuntu0.3
released
lucid
dne
libraw
disco
Fixed 0.15.3-1ubuntu1
released
cosmic
Fixed 0.15.3-1ubuntu1
released
bionic
Fixed 0.15.3-1ubuntu1
released
artful
Fixed 0.15.3-1ubuntu1
released
zesty
Fixed 0.15.3-1ubuntu1
released
yakkety
Fixed 0.15.3-1ubuntu1
released
xenial
Fixed 0.15.3-1ubuntu1
released
wily
Fixed 0.15.3-1ubuntu1
released
vivid
Fixed 0.15.3-1ubuntu1
released
utopic
Fixed 0.15.3-1ubuntu1
released
trusty
Fixed 0.15.3-1ubuntu1
released
saucy
Fixed 0.15.3-1ubuntu1
released
raring
Fixed 0.14.7-0ubuntu1.13.04.2
released
quantal
Fixed 0.14.7-0ubuntu1.12.10.2
released
precise
not-affected
lucid
dne