CVE-2015-3885
19.05.2015, 18:59
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dcraw_project | dcraw | 𝑥 ≤ 7.00 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||||||||||||
| dcraw |
| ||||||||||||||||||
| exactimage |
| ||||||||||||||||||
| freeimage |
| ||||||||||||||||||
| kodi |
| ||||||||||||||||||
| libraw |
| ||||||||||||||||||
| rawtherapee |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| dcraw |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| exactimage |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| freeimage |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| kodi |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| libraw |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| rawstudio |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| rawtherapee |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| ufraw |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| xbmc |
|
openSUSE / SLES Releases
Common Weakness Enumeration
References