CVE-2015-3885: Buffer Overflow
Published May 19, 2015
·Updated
Integer overflow in the ljpegstart function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
Affected Software
2 affected components
Dcraw Project Dcraw<=7.00
Fedoraproject Fedora=21
Event History
May 19, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3885?
CVE-2015-3885 has a severity rating that indicates it can lead to a denial of service due to a crash.
2
How do I fix CVE-2015-3885?
To fix CVE-2015-3885, upgrade to a version of dcraw that is newer than 7.00.
3
Who is affected by CVE-2015-3885?
CVE-2015-3885 primarily affects users of dcraw version 7.00 and earlier, particularly on Fedora 21.
4
What is the nature of the vulnerability in CVE-2015-3885?
CVE-2015-3885 is an integer overflow vulnerability in the ljpeg_start function that can cause a buffer overflow.
5
Can CVE-2015-3885 be exploited remotely?
Yes, CVE-2015-3885 can be exploited remotely by attackers using crafted images to trigger the vulnerability.