The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
2013-09-16T19:14:37.693
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libraw | libraw | 0.13.0 | Yes |
Application | libraw | libraw | 0.13.1 | Yes |
Application | libraw | libraw | 0.13.2 | Yes |
Application | libraw | libraw | 0.13.3 | Yes |
Application | libraw | libraw | 0.13.4 | Yes |
Application | libraw | libraw | 0.13.5 | Yes |
Application | libraw | libraw | 0.13.6 | Yes |
Application | libraw | libraw | 0.13.7 | Yes |
Application | libraw | libraw | 0.13.8 | Yes |
Application | libraw | libraw | 0.14.0 | Yes |
Application | libraw | libraw | 0.14.1 | Yes |
Application | libraw | libraw | 0.14.2 | Yes |
Application | libraw | libraw | 0.14.3 | Yes |
Application | libraw | libraw | 0.14.4 | Yes |
Application | libraw | libraw | 0.14.5 | Yes |
Application | libraw | libraw | 0.14.6 | Yes |
Application | libraw | libraw | 0.14.7 | Yes |
Application | libraw | libraw | 0.15.0 | Yes |
Application | libraw | libraw | 0.15.1 | Yes |
Application | libraw | libraw | 0.15.2 | Yes |
Application | libraw | libraw | 0.15.3 | Yes |