CVE-2013-2127

Publication date 14 August 2013

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the exposure correction code in LibRaw before 0.15.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

Read the notes from the security team

Status

Package Ubuntu Release Status
darktable 13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release
libkdcraw 13.04 raring
Fixed 4:4.10.2-0ubuntu1.1
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release
libraw 13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release

Notes


mdeslaur

only affects 0.15.x darktable embeds 0.14.x libkdcraw embeds 0.15.x on raring+

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libraw