CVE-2015-3885
published 2015-05-19CVE-2015-3885: Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which…
medium4.3CVSS 3.1
AVNACMAuNCNINAP
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dcraw_project | dcraw | <= 7.00 | — |
| dcraw_project | dcraw | >= 0 < 9.26-1 | 9.26-1 |
| dcraw_project | dcraw | >= 0 < 9.26-1 | 9.26-1 |
| dcraw_project | dcraw | >= 0 < 9.26-1 | 9.26-1 |
| dcraw_project | dcraw | >= 0 < 9.26-1 | 9.26-1 |
| debian | darktable | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| debian | dcraw | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| debian | exactimage | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| debian | freeimage | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| debian | kodi | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| debian | libraw | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| debian | rawtherapee | < darktable 1.6.7-1 (bookworm) | darktable 1.6.7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| freeimage_project | freeimage | >= 0 < 3.15.4-6 | 3.15.4-6 |
| freeimage_project | freeimage | >= 0 < 3.15.4-6 | 3.15.4-6 |
| freeimage_project | freeimage | >= 0 < 3.15.4-6 | 3.15.4-6 |
| freeimage_project | freeimage | >= 0 < 3.15.4-6 | 3.15.4-6 |
| kodi | kodi | >= 0 < 16.0+dfsg1-1 | 16.0+dfsg1-1 |
| kodi | kodi | >= 0 < 16.0+dfsg1-1 | 16.0+dfsg1-1 |
| kodi | kodi | >= 0 < 16.0+dfsg1-1 | 16.0+dfsg1-1 |
| libraw | libraw | >= 0 < 0.16.2-1 | 0.16.2-1 |
| libraw | libraw | >= 0 < 0.16.2-1 | 0.16.2-1 |
| libraw | libraw | >= 0 < 0.16.2-1 | 0.16.2-1 |
| libraw | libraw | >= 0 < 0.16.2-1 | 0.16.2-1 |
CVSS provenance
nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM