CVE-2013-1438
published 2014-01-19CVE-2013-1438: Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.06%
79.2th percentile
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dave_coffin | dcraw | — | — |
| dcraw_project | dcraw | >= 0 < 9.28-1 | 9.28-1 |
| dcraw_project | dcraw | >= 0 < 9.28-1 | 9.28-1 |
| dcraw_project | dcraw | >= 0 < 9.28-1 | 9.28-1 |
| dcraw_project | dcraw | >= 0 < 9.28-1 | 9.28-1 |
| debian | darktable | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | dcraw | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | exactimage | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | libkdcraw | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | libraw | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | rawtherapee | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| libraw | libraw | >= 0 < 0.15.4-1 | 0.15.4-1 |
| libraw | libraw | >= 0 < 0.15.4-1 | 0.15.4-1 |
| libraw | libraw | >= 0 < 0.15.4-1 | 0.15.4-1 |
| libraw | libraw | >= 0 < 0.15.4-1 | 0.15.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libKDcraw vulnerabilities
vendor_ubuntu·2013-09-30·CVSS 4.3
CVE-2013-1438 [MEDIUM] libKDcraw vulnerabilities
Title: libKDcraw vulnerabilities
Summary: libKDcraw could be made to crash if it opened a specially crafted file.
It was discovered that libKDcraw incorrectly handled photo files. If a user
or automated system were tricked into processing a specially crafted photo
file, applications linked against libKDcraw could be made to crash,
resulting in a denial of service. (CVE-2013-1438, CVE-2013-1439)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2013-09-23·CVSS 4.3
CVE-2013-1438 [MEDIUM] LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: LibRaw could be made to crash if it opened a specially crafted file.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, applications linked against LibRaw could be made to crash, resulting
in a denial of service. (CVE-2013-1438, CVE-2013-1439)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
LibRaw: multiple denial of service flaws
vendor_redhat·2013-08-28·CVSS 4.3
CVE-2013-1438 [MEDIUM] LibRaw: multiple denial of service flaws
LibRaw: multiple denial of service flaws
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: dcraw (Red Hat Enterprise Linux 5) - Will not fix
Package: dcraw (Red Hat Enterprise Linux 6) - Will not fix
Package: dcraw (Red Hat Enterprise Linux 7) - Will not f
Debian
CVE-2013-1438: darktable - Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw...
vendor_debian·2013·CVSS 4.3
CVE-2013-1438 [MEDIUM] CVE-2013-1438: darktable - Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw...
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 1.2.2-2)
bullseye: resolved (fixed in 1.2.2-2)
forky: resolved (fixed in 1.2.2-2)
sid: resolved (fixed in 1.2.2-2)
trixie: resolved (fixed in 1.2.2-2)
GHSA
GHSA-h3x3-43mf-g7c4: Unspecified vulnerability in dcraw 0
ghsa_unreviewed·2022-05-17
CVE-2013-1438 [MEDIUM] GHSA-h3x3-43mf-g7c4: Unspecified vulnerability in dcraw 0
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
OSV
CVE-2013-1438: Unspecified vulnerability in dcraw 0
osv·2014-01-19·CVSS 4.3
CVE-2013-1438 [MEDIUM] CVE-2013-1438: Unspecified vulnerability in dcraw 0
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1439 CVE-2013-1438 rawtherapee: LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2014-02-10·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 rawtherapee: LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 rawtherapee: LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
Bugzilla
CVE-2014-1438 kernel: x86: exceptions are not cleared in AMD FXSAVE workaround
bugzilla·2014-01-14·CVSS 4.7
CVE-2014-1438 [MEDIUM] CVE-2014-1438 kernel: x86: exceptions are not cleared in AMD FXSAVE workaround
CVE-2014-1438 kernel: x86: exceptions are not cleared in AMD FXSAVE workaround
Linux kernel is found to be vulnerable to a NULL pointer dereference flaw
caused due to inappropriate handling of Floating Point Unit(FPU) exceptions
during task switch at 'emms' instruction. This only affects AMD CPU family
in both i386 & AMD64 modes.
A user/program could use this flaw to kill tasks at random resulting in DoS
or potentially gain root privileges if allowed to map NULL(mmap_min_addr=0)
page.
Upstream fix:
-> https://git.kernel.org/linus/26bef1318adc1b3a530ecc807ef99346db2aa8b0
Reference:
-> https://lkml.org/lkml/2013/12/28/95
-> http://www.openwall.com/lists/oss-security/2014/01/12/1
-> http://www.halfdog.net/Security/2013/Vm86SyscallTaskSwitchKernelPanic/
Discussion:
Statement:
This issue
Bugzilla
CVE-2013-1439 CVE-2013-1438 ufraw: LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2013-10-01·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 ufraw: LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 ufraw: LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-1439 CVE-2013-1438 dcraw: LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2013-09-25·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 dcraw: LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 dcraw: LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws
bugzilla·2013-08-29·CVSS 4.3
CVE-2013-1438 [MEDIUM] CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws
CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws
Raphael Geissert reported two denial of service flaws in LibRaw [1]:
CVE-2013-1438:
Specially crafted photo files may trigger a division by zero, an
infinite loop, or a null pointer dereference in libraw leading to
denial of service in applications using the library.
These vulnerabilities appear to originate in dcraw and as such any
program or library based on it is affected. To name a few confirmed
applications: dcraw, ufraw. Other affected software: shotwell,
darktable, and libkdcraw (Qt-style interface to libraw, using embedded
copy) which is used by digikam.
Google Picasa apparently uses dcraw/ufraw so it might be affected.
dcraw's homepage has a list of applications that possibly still use
it:
http://cybercom.net
Bugzilla
CVE-2013-1439 CVE-2013-1438 LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2013-08-29·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
http://www.debian.org/security/2013/dsa-2748http://www.openwall.com/lists/oss-security/2013/08/29/3http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/62060http://www.debian.org/security/2013/dsa-2748http://www.openwall.com/lists/oss-security/2013/08/29/3http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/62060
2014-01-19
Published