CVE-2013-1438
exactimage - denial of service
EPSS 2.1%
描述
Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.
如何修補 CVE-2013-1438
要修補 CVE-2013-1438,請將受影響套件升級到下列已修補版本。
- Debian/darktable—升級至 1.2.2-2 或更新版本
- Debian/dcraw—升級至 9.28-1 或更新版本
- Debian/exactimage—升級至 0.8.9-1 或更新版本
- —升級至 0.8.1-3+deb6u2 或更新版本
- —升級至 24.12.0-1 或更新版本
- —升級至 0.15.4-1 或更新版本
CVE-2013-1438 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(6)
- from 0, < 1.2.2-2
- from 0, < 9.28-1
- from 0, < 0.8.9-1
- from 0, < 0.8.1-3+deb6u2
- from 0, < 24.12.0-1
- from 0, < 0.15.4-1