cbcvebase.
CVE-2013-2126
published 2013-08-14

CVE-2013-2126: Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a…

PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.41%
90.3th percentile
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandarktable< darktable 1.2.1-2 (bookworm)darktable 1.2.1-2 (bookworm)
debianlibkdcraw< darktable 1.2.1-2 (bookworm)darktable 1.2.1-2 (bookworm)
debianlibraw< darktable 1.2.1-2 (bookworm)darktable 1.2.1-2 (bookworm)
librawlibraw<= 0.15.1
librawlibraw
librawlibraw>= 0 < 0.15.3-10.15.3-1
librawlibraw>= 0 < 0.15.3-10.15.3-1
librawlibraw>= 0 < 0.15.3-10.15.3-1
librawlibraw>= 0 < 0.15.3-10.15.3-1
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.