CVE Vulnerabilities

CVE-2013-2126

Published: Aug 14, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

Affected Software

NameVendorStart VersionEnd Version
LibrawLibraw*0.15.1 (including)
LibrawLibraw0.15.0 (including)0.15.0 (including)
DarktableUbuntuprecise*
DarktableUbuntuquantal*
DarktableUbunturaring*
DarktableUbuntusaucy*
DarktableUbuntuupstream*
DarktableUbuntuutopic*
DarktableUbuntuvivid*
DarktableUbuntuwily*
LibkdcrawUbuntudevel*
LibkdcrawUbuntuesm-apps/xenial*
LibkdcrawUbuntuprecise*
LibkdcrawUbuntuquantal*
LibkdcrawUbunturaring*
LibkdcrawUbuntusaucy*
LibkdcrawUbuntutrusty*
LibkdcrawUbuntuutopic*
LibkdcrawUbuntuvivid*
LibkdcrawUbuntuwily*
LibkdcrawUbuntuxenial*
LibkdcrawUbuntuyakkety*
LibkdcrawUbuntuzesty*
LibrawUbuntudevel*
LibrawUbuntuesm-infra/xenial*
LibrawUbuntuprecise*
LibrawUbuntuquantal*
LibrawUbunturaring*
LibrawUbuntusaucy*
LibrawUbuntutrusty*
LibrawUbuntuupstream*
LibrawUbuntuutopic*
LibrawUbuntuvivid*
LibrawUbuntuwily*
LibrawUbuntuxenial*
LibrawUbuntuyakkety*
LibrawUbuntuzesty*

References