LibRaw CVE-2013-1438 Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
BID:62060
Info
LibRaw CVE-2013-1438 Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
| Bugtraq ID: | 62060 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-1438 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2013 12:00AM |
| Updated: | Jan 04 2016 02:28AM |
| Credit: | Raphael Geissert |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
LibRaw CVE-2013-1438 Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
LibRaw is prone to multiple denial-of-service vulnerabilities caused by NULL-pointer dereference errors.
An attacker can exploit these issues to crash the application running the affected library, denying service to legitimate users.
LibRaw versions 0.8 through 0.15.3 are vulnerable.
LibRaw is prone to multiple denial-of-service vulnerabilities caused by NULL-pointer dereference errors.
An attacker can exploit these issues to crash the application running the affected library, denying service to legitimate users.
LibRaw versions 0.8 through 0.15.3 are vulnerable.
Exploit / POC
LibRaw CVE-2013-1438 Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
LibRaw CVE-2013-1438 Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
LibRaw CVE-2013-1438 Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
References:
References: