MGASA-2015-0222
Dashboard / Vulnerabilities / MGASA-2015-0222
Summary: Updated darktable packages fix CVE-2015-3885
Details: Updated darktable package fixes security vulnerability The dcraw tool bundled in darktable's libraw copy suffers from an integer overflow condition which leads to a buffer overflow. A maliciously crafted raw image file can be used to trigger the vulnerability, causing a Denial of Service condition. The bundled dcraw code has been patched to fix this vulnerability.
References: https://advisories.mageia.org/MGASA-2015-0222.html, https://bugs.mageia.org/show_bug.cgi?id=15915, https://bugs.mageia.org/show_bug.cgi?id=15910, http://www.ocert.org/advisories/ocert-2015-006.html, http://openwall.com/lists/oss-security/2015/05/12/8
Affected packages
Package
Name: darktable
Purl: pkg:rpm/mageia/darktable?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
