CVE-2013-1439
published 2013-09-16CVE-2013-1439: The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.79%
76.1th percentile
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | darktable | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | libkdcraw | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| debian | libraw | < darktable 1.2.2-2 (bookworm) | darktable 1.2.2-2 (bookworm) |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.15.4-1 | 0.15.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libKDcraw vulnerabilities
vendor_ubuntu·2013-09-30·CVSS 4.3
CVE-2013-1438 [MEDIUM] libKDcraw vulnerabilities
Title: libKDcraw vulnerabilities
Summary: libKDcraw could be made to crash if it opened a specially crafted file.
It was discovered that libKDcraw incorrectly handled photo files. If a user
or automated system were tricked into processing a specially crafted photo
file, applications linked against libKDcraw could be made to crash,
resulting in a denial of service. (CVE-2013-1438, CVE-2013-1439)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2013-09-23·CVSS 4.3
CVE-2013-1438 [MEDIUM] LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: LibRaw could be made to crash if it opened a specially crafted file.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, applications linked against LibRaw could be made to crash, resulting
in a denial of service. (CVE-2013-1438, CVE-2013-1439)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
LibRaw: multiple denial of service flaws
vendor_redhat·2013-08-28·CVSS 4.3
CVE-2013-1439 [MEDIUM] LibRaw: multiple denial of service flaws
LibRaw: multiple denial of service flaws
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: dcraw (Red Hat Enterprise Linux 5) - Will not fix
Package: dcraw (Red Hat Enterprise Linux 6) - Will not fix
Package: dcraw (Red Hat Enterprise Linux 7) - Will not fix
Package: LibRaw (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2013-1439: darktable - The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 al...
vendor_debian·2013·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439: darktable - The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 al...
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
Scope: local
bookworm: resolved (fixed in 1.2.2-2)
bullseye: resolved (fixed in 1.2.2-2)
forky: resolved (fixed in 1.2.2-2)
sid: resolved (fixed in 1.2.2-2)
trixie: resolved (fixed in 1.2.2-2)
GHSA
GHSA-rcvp-8v7c-m59p: The "faster LJPEG decoder" in libraw 0
ghsa_unreviewed·2022-05-17
CVE-2013-1439 [MEDIUM] GHSA-rcvp-8v7c-m59p: The "faster LJPEG decoder" in libraw 0
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
OSV
CVE-2013-1439: The "faster LJPEG decoder" in libraw 0
osv·2013-09-16·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439: The "faster LJPEG decoder" in libraw 0
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1439 CVE-2013-1438 rawtherapee: LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2014-02-10·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 rawtherapee: LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 rawtherapee: LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
Bugzilla
CVE-2013-1439 CVE-2013-1438 ufraw: LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2013-10-01·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 ufraw: LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 ufraw: LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-1439 CVE-2013-1438 dcraw: LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2013-09-25·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 dcraw: LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 dcraw: LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws
bugzilla·2013-08-29·CVSS 4.3
CVE-2013-1438 [MEDIUM] CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws
CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws
Raphael Geissert reported two denial of service flaws in LibRaw [1]:
CVE-2013-1438:
Specially crafted photo files may trigger a division by zero, an
infinite loop, or a null pointer dereference in libraw leading to
denial of service in applications using the library.
These vulnerabilities appear to originate in dcraw and as such any
program or library based on it is affected. To name a few confirmed
applications: dcraw, ufraw. Other affected software: shotwell,
darktable, and libkdcraw (Qt-style interface to libraw, using embedded
copy) which is used by digikam.
Google Picasa apparently uses dcraw/ufraw so it might be affected.
dcraw's homepage has a list of applications that possibly still use
it:
http://cybercom.net
Bugzilla
CVE-2013-1439 CVE-2013-1438 LibRaw: multiple denial of service flaws [fedora-all]
bugzilla·2013-08-29·CVSS 4.3
CVE-2013-1439 [MEDIUM] CVE-2013-1439 CVE-2013-1438 LibRaw: multiple denial of service flaws [fedora-all]
CVE-2013-1439 CVE-2013-1438 LibRaw: multiple denial of service flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
http://www.debian.org/security/2013/dsa-2748http://www.openwall.com/lists/oss-security/2013/08/29/3https://github.com/LibRaw/LibRaw/commit/11909cc59e712e09b508dda729b99aeaac2b29adhttp://www.debian.org/security/2013/dsa-2748http://www.openwall.com/lists/oss-security/2013/08/29/3https://github.com/LibRaw/LibRaw/commit/11909cc59e712e09b508dda729b99aeaac2b29ad
2013-09-16
Published