CVE-2013-2126
Publication date 31 May 2013
Last updated 24 July 2024
Ubuntu priority
Description
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| darktable | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
| libkdcraw | ||
| 16.04 LTS xenial |
Fixed 4:4.10.4-0ubuntu2
|
|
| 14.04 LTS trusty |
Fixed 4:4.10.4-0ubuntu2
|
|
| libraw | ||
| 16.04 LTS xenial |
Fixed 0.14.7-2ubuntu1
|
|
| 14.04 LTS trusty |
Fixed 0.14.7-2ubuntu1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-1885-1
- libKDcraw vulnerability
- 18 June 2013
- USN-1884-1
- LibRaw vulnerability
- 18 June 2013