A buffer over-read in cropmaskedpixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
{ "binaries": [ { "binary_version": "9.21-0.2", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.27-1ubuntu1", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-2", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-3", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-5ubuntu1", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-8", "binary_name": "dcraw" } ] }