Lucene search

K
mageiaGentoo FoundationMGASA-2014-0050
HistoryFeb 11, 2014 - 12:21 a.m.

Updated darktable package fixes two vulnerabilities

2014-02-1100:21:49
Gentoo Foundation
advisories.mageia.org
18

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.002

Percentile

60.9%

Updated darktable package fixes security vulnerabilities: Darktable before version 1.2.3 contains an embedded copy of LibRaw that incorrectly handled photo files. If a user was tricked into processing a specially crafted photo file, darktable could be made to crash, resulting in a denial of service (CVE-2013-1438, CVE-2013-1439).

OSVersionArchitecturePackageVersionFilename
Mageia3noarchdarktable< 1.2-1.2darktable-1.2-1.2.mga3

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.002

Percentile

60.9%