Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libkdcrawUpgrade librawUpgrade darktable | Jul 30, 2024 | Aug 14, 2013 |
| Gentoo Linux | — | Upgrade media-libs/libraw.Upgrade kde-base/libkdcraw. | Oct 30, 2017 | Aug 14, 2013 |
| Suse | — | Upgrade libkdcrawUpgrade libraw-toolsUpgrade libraw-develUpgrade librawUpgrade libkdcraw20Upgrade libkdcraw-develUpgrade libraw5Upgrade darktableUpgrade darktable-docUpgrade libraw-devel-static | Dec 12, 2013 | Aug 14, 2013 |
| Ubuntu | — | Upgrade libraw5Upgrade libkdcraw20 | Nov 8, 2024 | Aug 14, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub