MGASA-2015-0222

Source
https://advisories.mageia.org/MGASA-2015-0222.html
Import Source
https://advisories.mageia.org/MGASA-2015-0222.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0222
Related
Published
2015-05-13T17:18:54Z
Modified
2015-05-13T17:07:30Z
Summary
Updated darktable packages fix CVE-2015-3885
Details

Updated darktable package fixes security vulnerability

The dcraw tool bundled in darktable's libraw copy suffers from an integer overflow condition which leads to a buffer overflow. A maliciously crafted raw image file can be used to trigger the vulnerability, causing a Denial of Service condition.

The bundled dcraw code has been patched to fix this vulnerability.

References
Credits

Affected packages

Mageia:4 / darktable

Package

Name
darktable
Purl
pkg:rpm/mageia/darktable?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.3-4.3.mga4

Ecosystem specific

{
    "section": "core"
}