From ${URL} : #2015-006 dcraw input sanitization errors Description: The dcraw photo decoder is an open source project for raw image parsing. The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition which lead to a buffer overflow. The vulnerability concerns the 'len' variable, parsed without validation from opened images, used in the ljpeg_start() function. A maliciously crafted raw image file can be used to trigger the vulnerability, causing a Denial of Service condition. Affected version: dcraw >= 7.00 UFRaw >= 0.5 LibRaw <= 0.16.0, 0.17-Alpha2 RawTherapee >= 3.0 CxImage >= 6.00 Rawstudio >= 0.1 Kodi >= 10.0 ExactImage >= 0.1.0 Fixed version: dcraw, N/A UFRaw, N/A LibRaw >= 0.16.1, 0.17-Alpha3 RawTherapee, N/A CxImage, N/A Rawstudio, N/A Kodi, N/A ExactImage, N/A Credit: vulnerability report from Eduardo Castellanos <guayin [at] gmail [dot] com>. CVE: N/A Timeline: 2015-04-24: vulnerability report received 2015-04-27: contacted dcraw maintainer 2015-04-30: patch provided by maintainer 2015-05-04: reporter confirms patch 2015-05-11: contacted additional affected vendors 2015-05-11: advisory release References: https://github.com/LibRaw/LibRaw/commit/4606c28f494a750892c5c1ac7903e62dd1c6fdb5 https://github.com/rawstudio/rawstudio/commit/983bda1f0fa5fa86884381208274198a620f006e Permalink: http://www.ocert.org/advisories/ocert-2015-006.html @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
CVE-2015-3885 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3885): Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
@ Arches, please test and mark stable: =media-gfx/dcraw-9.27.0
Stable on alpha.
amd64 stable
x86 stable
arm stable
ppc stable
ppc64 stable
sparc stable
Stable for HPPA.
ia64 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one.
vulnerable versions removed.
New GLSA request filed.
This issue was resolved and addressed in GLSA 201701-54 at https://security.gentoo.org/glsa/201701-54 by GLSA coordinator Aaron Bauman (b-man).