Lucene search

K
freebsdFreeBSD57325ECF-FACC-11E4-968F-B888E347C638
HistoryApr 24, 2015 - 12:00 a.m.

dcraw -- integer overflow condition

2015-04-2400:00:00
vuxml.freebsd.org
20

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.048

Percentile

92.7%

ocert reports:

The dcraw tool, as well as several other projects re-using its
code, suffers from an integer overflow condition which lead to a
buffer overflow.
The vulnerability concerns the ‘len’ variable, parsed without
validation from opened images, used in the ljpeg_start()
function.
A maliciously crafted raw image file can be used to trigger the
vulnerability, causing a Denial of Service condition.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.048

Percentile

92.7%