There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
{ "binaries": [ { "binary_version": "9.21-0.2", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.27-1ubuntu1", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-2", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-3", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-5ubuntu1", "binary_name": "dcraw" } ] }
{ "binaries": [ { "binary_version": "9.28-8", "binary_name": "dcraw" } ] }