4.3
CVSSv2

CVE-2015-3885

Published: 19/05/2015 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the ljpeg_start function in dcraw 7.00 and previous versions allows remote malicious users to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

Vulnerable Product Search on Vulmon Subscribe to Product

dcraw project dcraw

fedoraproject fedora 21

Vendor Advisories

LibRaw could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #839827 freeimage: CVE-2016-5684 Package: src:freeimage; Maintainer for src:freeimage is Debian Science Maintainers <debian-science-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 5 Oct 2016 13:09:01 UTC Severity: grave Tags: security, u ...
Debian Bug report logs - #785019 dcraw: CVE-2015-3885: input sanitization flaw leading to buffer overflow Package: dcraw; Maintainer for dcraw is Debian Astronomy Team <debian-astro-maintainers@listsaliothdebianorg>; Source for dcraw is src:dcraw (PTS, buildd, popcon) Reported by: "Karl O Pinc" <kop@memecom> Dat ...
Multiple vulnerabilities were discovered in the FreeImage multimedia library, which might result in denial of service or the execution of arbitrary code if a malformed XMP or RAW image is processed For the stable distribution (jessie), these problems have been fixed in version 3154-42+deb8u1 For the testing distribution (stretch), these proble ...
A flaw was discovered in the way dcraw processed Raw images An attacker could use this flaw to cause dcraw to crash by tricking a user into processing a specially crafted Raw image file ...