First published: Mon Sep 16 2013(Updated: )
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
LibRaw | =0.13.0 | |
LibRaw | =0.13.1 | |
LibRaw | =0.13.2 | |
LibRaw | =0.13.3 | |
LibRaw | =0.13.4 | |
LibRaw | =0.13.5 | |
LibRaw | =0.13.6 | |
LibRaw | =0.13.7 | |
LibRaw | =0.13.8 | |
LibRaw | =0.14.0 | |
LibRaw | =0.14.1 | |
LibRaw | =0.14.2 | |
LibRaw | =0.14.3 | |
LibRaw | =0.14.4 | |
LibRaw | =0.14.5 | |
LibRaw | =0.14.6 | |
LibRaw | =0.14.7 | |
LibRaw | =0.15.0 | |
LibRaw | =0.15.1 | |
LibRaw | =0.15.2 | |
LibRaw | =0.15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1439 has a severity rating that typically falls into medium or high due to the potential for a denial of service attack.
To fix CVE-2013-1439, update LibRaw to version 0.15.4 or later.
CVE-2013-1439 affects LibRaw versions 0.13.x, 0.14.x, and 0.15.x prior to 0.15.4.
CVE-2013-1439 is a denial of service vulnerability resulting from a NULL pointer dereference in the faster LJPEG decoder.
CVE-2013-1439 can be exploited by context-dependent attackers using crafted photo files.