CVE-2013-2126
14.08.2013, 15:55
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.Enginsight
Vendor | Product | Version |
---|---|---|
libraw | libraw | 𝑥 ≤ 0.15.1 |
libraw | libraw | 0.15.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 12.10 |
canonical | ubuntu_linux | 13.04 |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
darktable |
| ||||||||||||||||||||||||
libkdcraw |
| ||||||||||||||||||||||||
libraw |
|
Common Weakness Enumeration
References