CVE-2013-2126
published 2013-08-14CVE-2013-2126: Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.41%
90.3th percentile
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | darktable | < darktable 1.2.1-2 (bookworm) | darktable 1.2.1-2 (bookworm) |
| debian | libkdcraw | < darktable 1.2.1-2 (bookworm) | darktable 1.2.1-2 (bookworm) |
| debian | libraw | < darktable 1.2.1-2 (bookworm) | darktable 1.2.1-2 (bookworm) |
| libraw | libraw | <= 0.15.1 | — |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.15.3-1 | 0.15.3-1 |
| libraw | libraw | >= 0 < 0.15.3-1 | 0.15.3-1 |
| libraw | libraw | >= 0 < 0.15.3-1 | 0.15.3-1 |
| libraw | libraw | >= 0 < 0.15.3-1 | 0.15.3-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibRaw vulnerability
vendor_ubuntu·2013-06-18
CVE-2013-2126 LibRaw vulnerability
Title: LibRaw vulnerability
Summary: LibRaw could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that LibRaw incorrectly handled broken full-color images.
If a user or automated system were tricked into processing a specially
crafted raw image, applications linked against LibRaw could be made to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Ubuntu
libKDcraw vulnerability
vendor_ubuntu·2013-06-18
CVE-2013-2126 libKDcraw vulnerability
Title: libKDcraw vulnerability
Summary: libKDcraw could be made to crash or run programs as your login if it opened
a specially crafted file.
It was discovered that libKDcraw incorrectly handled broken full-color
images. If a user or automated system were tricked into processing a
specially crafted raw image, applications linked against libKDcraw could be
made to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files
vendor_redhat·2013-05-24·CVSS 7.5
CVE-2013-2126 [HIGH] LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files
LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
Package: libkdcraw (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-2126: darktable - Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cx...
vendor_debian·2013·CVSS 7.5
CVE-2013-2126 [HIGH] CVE-2013-2126: darktable - Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cx...
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
Scope: local
bookworm: resolved (fixed in 1.2.1-2)
bullseye: resolved (fixed in 1.2.1-2)
forky: resolved (fixed in 1.2.1-2)
sid: resolved (fixed in 1.2.1-2)
trixie: resolved (fixed in 1.2.1-2)
GHSA
GHSA-f8qw-gp3p-w497: Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx
ghsa_unreviewed·2022-05-14
CVE-2013-2126 [HIGH] GHSA-f8qw-gp3p-w497: Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
OSV
CVE-2013-2126: Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx
osv·2013-08-14·CVSS 7.5
CVE-2013-2126 [HIGH] CVE-2013-2126: Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files [fedora-all]
bugzilla·2013-06-04·CVSS 7.5
CVE-2013-2126 [HIGH] CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files [fedora-all]
CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files [fedora-all]
bugzilla·2013-06-04·CVSS 7.5
CVE-2013-2126 [HIGH] CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files [fedora-all]
CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files
bugzilla·2013-05-29·CVSS 7.5
CVE-2013-2126 [HIGH] CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files
CVE-2013-2126 LibRaw: double-free flaw when handling damaged full-color in Foveon and sRAW files
LibRaw 0.15.2 notes the following fix [1]:
* Fixed possible double call to free() on error recovery on damaged full-color (Foveon, sRAW) files.
Successful exploitation could allow for the execution of arbitrary code with the privileges of the user running an application linked to LibRaw.
This has been fixed in LibRaw 0.15.2 [2].
[1] http://www.libraw.org/news/libraw-0-15-2
[2] https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6
Discussion:
Created LibRaw tracking bugs for this issue
Affects: fedora-all [bug 968387]
---
This seems to affect 0.15.x branch only, we ship only 0.14.x currently. Can you verify?
---
This has been assigned CVE-2013-2126 as per:
http://lists.opensuse.org/opensuse-updates/2013-06/msg00193.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00195.htmlhttp://secunia.com/advisories/53547http://secunia.com/advisories/53883http://secunia.com/advisories/53888http://secunia.com/advisories/53938http://www.libraw.org/news/libraw-0-15-2http://www.openwall.com/lists/oss-security/2013/05/29/7http://www.openwall.com/lists/oss-security/2013/06/10/1http://www.ubuntu.com/usn/USN-1884-1http://www.ubuntu.com/usn/USN-1885-1https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6http://lists.opensuse.org/opensuse-updates/2013-06/msg00193.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00195.htmlhttp://secunia.com/advisories/53547http://secunia.com/advisories/53883http://secunia.com/advisories/53888http://secunia.com/advisories/53938http://www.libraw.org/news/libraw-0-15-2http://www.openwall.com/lists/oss-security/2013/05/29/7http://www.openwall.com/lists/oss-security/2013/06/10/1http://www.ubuntu.com/usn/USN-1884-1http://www.ubuntu.com/usn/USN-1885-1https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6
2013-08-14
Published