RSS   Vulnerabilities for 'Dcraw'   RSS

2018-11-29
 
CVE-2018-19655

CWE-119
 

 
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

 
2018-11-26
 
CVE-2018-19568

CWE-119
 

 
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.

 
 
CVE-2018-19567

CWE-119
 

 
A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.

 
 
CVE-2018-19566

CWE-125
 

 
A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

 
 
CVE-2018-19565

CWE-125
 

 
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

 
2015-05-19
 
CVE-2015-3885

CWE-189
 

 
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

 


Copyright 2019, cxsecurity.com

 

Back to Top