A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
{
"binaries": [
{
"binary_version": "0.22-3.1~build0.18.04.1",
"binary_name": "gimp-ufraw"
},
{
"binary_version": "0.22-3.1~build0.18.04.1",
"binary_name": "ufraw"
},
{
"binary_version": "0.22-3.1~build0.18.04.1",
"binary_name": "ufraw-batch"
}
],
"availability": "No subscription required"
}