7.5
CVSSv2

CVE-2013-2126

Published: 14/08/2013 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw prior to 0.15.2 allow context-dependent malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

Vulnerable Product Search on Vulmon Subscribe to Product

libraw libraw 0.15.0

libraw libraw

opensuse opensuse 12.3

canonical ubuntu linux 12.10

opensuse opensuse 12.2

canonical ubuntu linux 13.04

canonical ubuntu linux 12.04

Vendor Advisories

Debian Bug report logs - #710353 libraw: CVE-2013-2126 CVE-2013-2127 Package: libraw; Maintainer for libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 30 May 2013 07:33:01 UTC Severity: grave Tags: patch, security Found ...
libKDcraw could be made to crash or run programs as your login if it opened a specially crafted file ...
LibRaw could be made to crash or run programs as your login if it opened a specially crafted file ...
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxxcpp in LibRaw before 0152 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file ...