Vulnerability CVE-2015-3885


Published: 2015-05-19

Description:
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

Type:

CWE-189

(Numeric Errors)

Vendor: Dcraw project
Product: Dcraw 
Version: 7.00;
Vendor: Fedoraproject
Product: Fedora 
Version: 21;

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162084.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159469.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159479.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159518.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159579.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159625.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159665.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159083.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159123.html
http://www.ocert.org/advisories/ocert-2015-006.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/archive/1/535513/100/0/threaded
http://www.securityfocus.com/bid/74590
https://github.com/LibRaw/LibRaw/commit/4606c28f494a750892c5c1ac7903e62dd1c6fdb5
https://github.com/rawstudio/rawstudio/commit/983bda1f0fa5fa86884381208274198a620f006e
https://security.gentoo.org/glsa/201701-54
https://security.gentoo.org/glsa/201706-17

Related CVE
CVE-2019-7165
A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
CVE-2019-5839
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
CVE-2019-5838
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
CVE-2019-5837
Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-5836
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-5835
Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2019-5834
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2019-5833
Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.

Copyright 2019, cxsecurity.com

 

Back to Top