FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  454327
Date:      2017-11-16
Time:      19:05:01Z
Committer: jkim

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
57325ecf-facc-11e4-968f-b888e347c638dcraw -- integer overflow condition

ocert reports:

The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition which lead to a buffer overflow.

The vulnerability concerns the 'len' variable, parsed without validation from opened images, used in the ljpeg_start() function.

A maliciously crafted raw image file can be used to trigger the vulnerability, causing a Denial of Service condition.


Discovery 2015-04-24
Entry 2015-05-15
Modified 2016-01-08
cinepaint
ge 0.22.0

darktable
lt 1.6.7

dcraw
ge 7.00 lt 9.26

dcraw-m
ge 0

exact-image
lt 0.9.1

flphoto
ge 0

freeimage
ge 3.13.0 lt 3.16.0_1

kodi
lt 14.2_1

libraw
lt 0.16.1

lightzone
lt 4.1.2

netpbm
lt 10.35.96

opengtl
ge 0

rawstudio
lt 2.0_11

ufraw
lt 0.21

CVE-2015-3885
http://www.ocert.org/advisories/ocert-2015-006.html
https://github.com/rawstudio/rawstudio/commit/983bda1f0fa5fa86884381208274198a620f006e
https://github.com/LibRaw/LibRaw/commit/4606c28f494a750892c5c1ac7903e62dd1c6fdb5
https://sourceforge.net/p/netpbm/code/2512/