CVE-2013-2126 REJECTED

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

EPSS 3.22% · 87.0th percentile

Risk Scores

EPSS Score
3.22%
87.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSdarktable0, 1.2.3-1ubuntu1, 1.4-1ubuntu1

Timeline

References

Open in Interactive Console →