ALT-PU-2023-8896-1
Closed vulnerabilities
Published: 2023-06-26
Modified: 2025-12-03
Modified: 2025-12-03
BDU:2023-03406
Уязвимость функции raw2image_ex() библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (6.5)Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Severity: HIGH (7.8)Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
References:
Published: 2023-05-15
Modified: 2025-03-20
Modified: 2025-03-20
CVE-2023-1729
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
Severity: MEDIUM (6.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- https://bugzilla.redhat.com/show_bug.cgi?id=2188240
- https://github.com/LibRaw/LibRaw/issues/557
- https://lists.debian.org/debian-lts-announce/2023/05/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGZ6XF5WTPJ4GLXQ62JVRDZSVSJHXNQU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E5ZJ3UBTJBZHNPJQFOSGM5L7WAHHE2GY/
- https://security.gentoo.org/glsa/202312-08
- https://www.debian.org/security/2023/dsa-5412
- https://bugzilla.redhat.com/show_bug.cgi?id=2188240
- https://github.com/LibRaw/LibRaw/issues/557
- https://lists.debian.org/debian-lts-announce/2023/05/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGZ6XF5WTPJ4GLXQ62JVRDZSVSJHXNQU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E5ZJ3UBTJBZHNPJQFOSGM5L7WAHHE2GY/
- https://security.gentoo.org/glsa/202312-08
- https://www.debian.org/security/2023/dsa-5412
