4.3
CVSSv2

CVE-2013-1439

Published: 16/09/2013 Updated: 15/11/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x prior to 0.15.4 allows context-dependent malicious users to cause a denial of service (NULL pointer dereference) via a crafted photo file.

Vulnerable Product Search on Vulmon Subscribe to Product

libraw libraw 0.13.7

libraw libraw 0.13.6

libraw libraw 0.13.5

libraw libraw 0.14.5

libraw libraw 0.14.4

libraw libraw 0.15.3

libraw libraw 0.13.0

libraw libraw 0.13.2

libraw libraw 0.13.1

libraw libraw 0.14.1

libraw libraw 0.15.0

libraw libraw 0.13.4

libraw libraw 0.13.3

libraw libraw 0.14.3

libraw libraw 0.14.2

libraw libraw 0.14.0

libraw libraw 0.13.8

libraw libraw 0.14.7

libraw libraw 0.14.6

libraw libraw 0.15.1

libraw libraw 0.15.2

Vendor Advisories

Debian Bug report logs - #721231 CVE-2013-1438: libraw: multiple vulnerabilities Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Raphael Geissert <geissert@debianorg> Date: Thu, 29 Aug 2013 10:03:01 UTC Severity: important T ...
Debian Bug report logs - #721338 CVE-2013-1438: libraw: multiple vulnerabilities Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Raphael Geissert <geissert@debianorg> Date: Fri, 30 Aug 2013 14:06:02 UTC Severity: important T ...
libKDcraw could be made to crash if it opened a specially crafted file ...
LibRaw could be made to crash if it opened a specially crafted file ...
The "faster LJPEG decoder" in libraw 013x, 014x, and 015x before 0154 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file ...