7.5

CVE-2013-2126

Exploit
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libraw ≫ Libraw Version <= 0.15.1
Libraw ≫ Libraw Version 0.15.0
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Opensuse ≫ Opensuse Version 12.2
Opensuse ≫ Opensuse Version 12.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.41% 0.901
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-updates/2013-06/msg00193.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00195.html
http://secunia.com/advisories/53547
Vendor Advisory
http://secunia.com/advisories/53883
Vendor Advisory
http://secunia.com/advisories/53888
Vendor Advisory
http://secunia.com/advisories/53938
http://www.libraw.org/news/libraw-0-15-2
http://www.openwall.com/lists/oss-security/2013/05/29/7
http://www.openwall.com/lists/oss-security/2013/06/10/1
http://www.ubuntu.com/usn/USN-1884-1
http://www.ubuntu.com/usn/USN-1885-1
https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6
Patch
Exploit