CVE-2013-2126: Double Free
Multiple double free vulnerabilities in the LibRaw::unpack function in librawcxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2126?
CVE-2013-2126 has been classified with a moderate severity rating due to its potential to cause application crashes and possible remote code execution.
How do I fix CVE-2013-2126?
To fix CVE-2013-2126, upgrade to LibRaw version 0.15.2 or later to patch the double free vulnerabilities.
Which versions of LibRaw are affected by CVE-2013-2126?
CVE-2013-2126 affects LibRaw versions prior to 0.15.2, including 0.15.0 and 0.15.1.
Is CVE-2013-2126 specific to any operating systems?
Yes, CVE-2013-2126 affects LibRaw on multiple operating systems including Ubuntu 12.04, 12.10, and 13.04, as well as openSUSE 12.2 and 12.3.
What types of files can trigger CVE-2013-2126?
CVE-2013-2126 can be triggered by malformed full-color Foveon or sRAW image files.