oss-sec mailing list archives

Re: CVE request: libraw: multiple issues


From: Raphael Geissert <geissert () debian org>
Date: Wed, 29 May 2013 11:18:06 +0200

Hi Kurt,

On 28 May 2013 19:58, Kurt Seifried <kseifried () redhat com> wrote:
On 05/28/2013 02:43 AM, Raphael Geissert wrote:
So there's a double-free (fixed in 0.15.2[3])

https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6

and a buffer overflow (fixed in 0.15.1[2]).

https://github.com/LibRaw/LibRaw/commit/2f912f5b33582961b1cdbd9fd828589f8b78f21d

Cheers,
--
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net


Current thread: