There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
{ "binaries": [ { "binary_name": "dcraw", "binary_version": "9.28-3" } ] }
{ "binaries": [ { "binary_name": "dcraw", "binary_version": "9.28-5ubuntu1" } ] }
{ "binaries": [ { "binary_name": "dcraw", "binary_version": "9.28-8" } ] }
{ "binaries": [ { "binary_name": "dcraw", "binary_version": "9.21-0.2" } ] }
{ "binaries": [ { "binary_name": "dcraw", "binary_version": "9.27-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "dcraw", "binary_version": "9.28-2" } ] }