Buffer overflow in the exposure correction code in LibRaw before 0.15.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
https://github.com/iridium-soda/VulnCodeCollector
https://github.com/LibRaw/LibRaw/commit/2f912f5b33582961b1cdbd9fd828589f8b78f21d
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2095
http://www.openwall.com/lists/oss-security/2013/05/29/7