Bugzilla – Bug 930683
VUL-1: CVE-2015-3885: dcraw,libraw,ufraw,netpbm: input sanitization errors
Last modified: 2022-04-07 08:35:20 UTC
From the oCERT advisory: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition which lead to a buffer overflow. The vulnerability concerns the 'len' variable, parsed without validation from opened images, used in the ljpeg_start() function. A maliciously crafted raw image file can be used to trigger the vulnerability, causing a Denial of Service condition. CVE-2015-3885 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3885 http://seclists.org/oss-sec/2015/q2/417 http://www.ocert.org/advisories/ocert-2015-006.html
Fixes: https://github.com/LibRaw/LibRaw/commit/4606c28f494a750892c5c1ac7903e62dd1c6fdb5 https://github.com/rawstudio/rawstudio/commit/983bda1f0fa5fa86884381208274198a620f006e
For libraw, see openSUSE: mr#306742 12: mr#57566
QA: no testcase found
bugbot adjusting priority
openSUSE-SU-2015:0931-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 930683 CVE References: CVE-2015-3885 Sources used: openSUSE 13.2 (src): libraw-0.16.0-2.3.1 openSUSE 13.1 (src): libraw-0.15.4-2.3.1
JFYI: http://www.darktable.org/2015/06/released-darktable-1-6-7/
Confirmed vulnerable code is in dcraw from SLE 10 on. -> Fridrich Confirmed vulnerable code is in ufraw on SLE 10 only, ignoring. Confirmed vulnerable code is in netpbm on SLE 12 only -> Petr ( netpbm-10.66.3/converter/other/cameratopam/ljpeg.h )
DoS requiring user interaction -> VUL-1
SUSE-SU-2017:2300-1: An update that fixes 7 vulnerabilities is now available. Category: security (moderate) Bug References: 1039209,1039210,1039379,1039380,930683,957517 CVE References: CVE-2015-3885,CVE-2015-8367,CVE-2017-6886,CVE-2017-6887,CVE-2017-6889,CVE-2017-6890,CVE-2017-6899 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP3 (src): libraw-0.15.4-9.2 SUSE Linux Enterprise Workstation Extension 12-SP2 (src): libraw-0.15.4-9.2 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): libraw-0.15.4-9.2 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libraw-0.15.4-9.2 SUSE Linux Enterprise Desktop 12-SP3 (src): libraw-0.15.4-9.2 SUSE Linux Enterprise Desktop 12-SP2 (src): libraw-0.15.4-9.2
close
.