4.3
CVSSv2

CVE-2013-1438

Published: 19/01/2014 Updated: 28/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Unspecified vulnerability in dcraw 0.8.x up to and including 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent malicious users to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dave coffin dcraw 0.8.6

dave coffin dcraw 0.8.5

dave coffin dcraw 0.8.4

dave coffin dcraw 0.8.3

dave coffin dcraw 0.8.9

dave coffin dcraw 0.8.2

dave coffin dcraw 0.8.1

dave coffin dcraw 0.8.8

dave coffin dcraw 0.8.7

dave coffin dcraw 0.8.0

Vendor Advisories

Debian Bug report logs - #721231 CVE-2013-1438: libraw: multiple vulnerabilities Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Raphael Geissert <geissert@debianorg> Date: Thu, 29 Aug 2013 10:03:01 UTC Severity: important T ...
Debian Bug report logs - #721338 CVE-2013-1438: libraw: multiple vulnerabilities Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Raphael Geissert <geissert@debianorg> Date: Fri, 30 Aug 2013 14:06:02 UTC Severity: important T ...
libKDcraw could be made to crash if it opened a specially crafted file ...
LibRaw could be made to crash if it opened a specially crafted file ...
Several denial-of-service vulnerabilities were discovered in the dcraw code base, a program for procesing raw format images from digital cameras This update corrects them in the copy that is embedded in the exactimage package For the oldstable distribution (squeeze), this problem has been fixed in version 081-3+deb6u2 For the stable distributi ...
Unspecified vulnerability in dcraw 08x through 089, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference ...