cbcvebase.
CVE-2013-1438
published 2014-01-19

CVE-2013-1438: Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a…

PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.06%
79.2th percentile
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.

Affected

24 ranges
VendorProductVersion rangeFixed in
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dave_coffindcraw
dcraw_projectdcraw>= 0 < 9.28-19.28-1
dcraw_projectdcraw>= 0 < 9.28-19.28-1
dcraw_projectdcraw>= 0 < 9.28-19.28-1
dcraw_projectdcraw>= 0 < 9.28-19.28-1
debiandarktable< darktable 1.2.2-2 (bookworm)darktable 1.2.2-2 (bookworm)
debiandcraw< darktable 1.2.2-2 (bookworm)darktable 1.2.2-2 (bookworm)
debianexactimage< darktable 1.2.2-2 (bookworm)darktable 1.2.2-2 (bookworm)
debianlibkdcraw< darktable 1.2.2-2 (bookworm)darktable 1.2.2-2 (bookworm)
debianlibraw< darktable 1.2.2-2 (bookworm)darktable 1.2.2-2 (bookworm)
debianrawtherapee< darktable 1.2.2-2 (bookworm)darktable 1.2.2-2 (bookworm)
librawlibraw>= 0 < 0.15.4-10.15.4-1
librawlibraw>= 0 < 0.15.4-10.15.4-1
librawlibraw>= 0 < 0.15.4-10.15.4-1
librawlibraw>= 0 < 0.15.4-10.15.4-1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.