Name | CVE-2013-1438 |
Description | Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-2748-1 |
Debian Bugs | 721231, 721232, 721233, 721234, 721235, 721236, 721237, 721239 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
darktable (PTS) | jessie | 1.4.2-1+deb8u1 | fixed |
stretch | 2.2.1-3 | fixed | |
buster | 2.6.0-1 | fixed | |
bullseye | 3.4.1-5 | fixed | |
bookworm | 4.2.1-4 | fixed | |
sid, trixie | 4.8.1-2 | fixed | |
dcraw (PTS) | jessie | 9.21-0.2 | vulnerable |
stretch | 9.27-1 | vulnerable | |
buster, bullseye | 9.28-2 | fixed | |
bookworm | 9.28-3 | fixed | |
sid, trixie | 9.28-7 | fixed | |
exactimage (PTS) | jessie, jessie (lts) | 0.8.9-7+deb8u3 | fixed |
stretch | 0.9.1-16 | fixed | |
buster | 1.0.2-1+deb10u1 | fixed | |
bullseye | 1.0.2-8 | fixed | |
bookworm | 1.0.2-11 | fixed | |
sid, trixie | 1.0.2-12 | fixed | |
libkdcraw (PTS) | jessie | 4:4.14.0-1 | fixed |
stretch | 4:15.08.0-1.1 | fixed | |
sid | 24.12.0-1 | vulnerable | |
libraw (PTS) | jessie, jessie (lts) | 0.16.0-9+deb8u6 | fixed |
stretch (security) | 0.17.2-6+deb9u2 | fixed | |
stretch (lts), stretch | 0.17.2-6+deb9u5 | fixed | |
buster (security), buster, buster (lts) | 0.19.2-2+deb10u4 | fixed | |
bullseye (security), bullseye | 0.20.2-1+deb11u1 | fixed | |
bookworm | 0.20.2-2.1 | fixed | |
sid, trixie | 0.21.3-1 | fixed | |
rawtherapee (PTS) | jessie | 4.2-1+deb8u2 | fixed |
stretch | 5.0-1 | fixed | |
buster | 5.5-1 | fixed | |
bullseye | 5.8-3 | fixed | |
bookworm | 5.9-1 | fixed | |
sid, trixie | 5.11-2 | fixed | |
ufraw (PTS) | jessie, jessie (lts) | 0.20-2+deb8u2 | fixed |
stretch | 0.22-1.1 | fixed | |
buster | 0.22-4 | fixed | |
xbmc (PTS) | jessie | 2:13.2+dfsg1-4 | vulnerable |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
darktable | source | wheezy | 1.0.4-1+deb7u2 | |||
darktable | source | (unstable) | 1.2.2-2 | 721233 | ||
dcraw | source | (unstable) | 9.28-1 | unimportant | 721232 | |
exactimage | source | squeeze | 0.8.1-3+deb6u2 | DSA-2748-1 | ||
exactimage | source | wheezy | 0.8.5-5+deb7u2 | DSA-2748-1 | ||
exactimage | source | (unstable) | 0.8.9-1 | 721236 | ||
libkdcraw | source | (unstable) | 4:4.10.5-2 | 721239 | ||
libraw | source | (unstable) | 0.15.4-1 | 721231 | ||
rawstudio | source | (unstable) | (unfixed) | unimportant | 721237 | |
rawtherapee | source | (unstable) | (not affected) | |||
ufraw | source | (unstable) | 0.19.2-2 | 721234 | ||
xbmc | source | (unstable) | 2:13.2+dfsg1-5 | unimportant | 721235 |
[wheezy] - libraw <no-dsa> (Minor issue)
[squeeze] - libraw <no-dsa> (Minor issue)
[wheezy] - libkdcraw <no-dsa> (Minor issue)
[wheezy] - ufraw <no-dsa> (end-user app)
[squeeze] - ufraw <no-dsa> (end-user app)
- rawtherapee <not-affected> (unimportant; bug #721238)
Starting with 2:13.2+dfsg1-5 xbmc is a transitional package