MGASA-2014-0011
Dashboard / Vulnerabilities / MGASA-2014-0011
Summary: Updated dcraw and ufraw package fix security vulnerability
Details: Due to flaws in the embedded copy of LibRaw in dcraw and ufraw, corrupt input files might trigger a division by zero, an infinite loop, or a null pointer dereference (CVE-2013-1438). The dcraw and ufraw packages have been updated to their newest versions and patched to fix the flaws in the embedded LibRaw library. They have also been patched to use the more secure lcms2 color management library, rather than the unmaintained lcms library.
References: https://advisories.mageia.org/MGASA-2014-0011.html, https://bugs.mageia.org/show_bug.cgi?id=12125, https://lists.fedoraproject.org/pipermail/package-announce/2013-December/124176.html, https://lists.fedoraproject.org/pipermail/package-announce/2013-December/124183.html
Affected packages
Package
Name: dcraw
Purl: pkg:rpm/mageia/dcraw?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
