Fedora 18 : LibRaw-0.14.8-3.fc18.20120830git98d925 (2013-15576)

Medium Nessus Plugin ID 69821


The remote Fedora host is missing a security update.


Raphael Geissert reported two denial of service flaws in LibRaw [1] :

CVE-2013-1438 :

Specially crafted photo files may trigger a division by zero, an infinite loop, or a NULL pointer dereference in libraw leading to denial of service in applications using the library. These vulnerabilities appear to originate in dcraw and as such any program or library based on it is affected. To name a few confirmed applications: dcraw, ufraw. Other affected software: shotwell, darktable, and libkdcraw (Qt-style interface to libraw, using embedded copy) which is used by digikam.

Google Picasa apparently uses dcraw/ufraw so it might be affected.
dcraw's homepage has a list of applications that possibly still use it: http://cybercom.net/~dcoffin/dcraw/

Affected versions of libraw: confirmed: 0.8-0.15.3; but it is likely that all versions are affected.

Fixed in: libraw 0.15.4

CVE-2013-1439 :

Specially crafted photo files may trigger a series of conditions in which a NULL pointer is dereferenced leading to denial of service in applications using the library. These three vulnerabilities are in/related to the 'faster LJPEG decoder', which upstream states was introduced in LibRaw 0.13 and support for which is going to be dropped in 0.16.

Affected versions of libraw: 0.13.x-0.15.x

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected LibRaw package.

See Also




Plugin Details

Severity: Medium

ID: 69821

File Name: fedora_2013-15576.nasl

Version: $Revision: 1.7 $

Type: local

Agent: unix

Published: 2013/09/10

Modified: 2015/10/19

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:LibRaw, cpe:/o:fedoraproject:fedora:18

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/08/30

Reference Information

CVE: CVE-2013-1438, CVE-2013-1439

BID: 62057, 62060

FEDORA: 2013-15576