A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.22-3.1~build0.18.04.1", "binary_name": "gimp-ufraw" }, { "binary_version": "0.22-3.1~build0.18.04.1", "binary_name": "gimp-ufraw-dbgsym" }, { "binary_version": "0.22-3.1~build0.18.04.1", "binary_name": "ufraw" }, { "binary_version": "0.22-3.1~build0.18.04.1", "binary_name": "ufraw-batch" }, { "binary_version": "0.22-3.1~build0.18.04.1", "binary_name": "ufraw-batch-dbgsym" }, { "binary_version": "0.22-3.1~build0.18.04.1", "binary_name": "ufraw-dbgsym" } ] }