Fedora 19 : LibRaw-0.14.8-3.fc19.20120830git98d925 (2013-15562)

medium Nessus Plugin ID 69820

Synopsis

The remote Fedora host is missing a security update.

Description

Raphael Geissert reported two denial of service flaws in LibRaw [1] :

CVE-2013-1438 :

Specially crafted photo files may trigger a division by zero, an infinite loop, or a NULL pointer dereference in libraw leading to denial of service in applications using the library. These vulnerabilities appear to originate in dcraw and as such any program or library based on it is affected. To name a few confirmed applications: dcraw, ufraw. Other affected software: shotwell, darktable, and libkdcraw (Qt-style interface to libraw, using embedded copy) which is used by digikam.

Google Picasa apparently uses dcraw/ufraw so it might be affected.
dcraw's homepage has a list of applications that possibly still use it: http://cybercom.net/~dcoffin/dcraw/

Affected versions of libraw: confirmed: 0.8-0.15.3; but it is likely that all versions are affected.

Fixed in: libraw 0.15.4

CVE-2013-1439 :

Specially crafted photo files may trigger a series of conditions in which a NULL pointer is dereferenced leading to denial of service in applications using the library. These three vulnerabilities are in/related to the 'faster LJPEG decoder', which upstream states was introduced in LibRaw 0.13 and support for which is going to be dropped in 0.16.

Affected versions of libraw: 0.13.x-0.15.x

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected LibRaw package.

See Also

http://cybercom.net/~dcoffin/dcraw/

https://bugzilla.redhat.com/show_bug.cgi?id=1002717

http://www.nessus.org/u?3517066a

Plugin Details

Severity: Medium

ID: 69820

File Name: fedora_2013-15562.nasl

Version: 1.9

Type: local

Agent: unix

Published: 9/10/2013

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:libraw, cpe:/o:fedoraproject:fedora:19

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/30/2013

Reference Information

CVE: CVE-2013-1438, CVE-2013-1439

BID: 62057, 62060

FEDORA: 2013-15562