CVE-2015-3885
freeimage - security update
EPSS 5.4%
描述
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
如何修補 CVE-2015-3885
要修補 CVE-2015-3885,請將受影響套件升級到下列已修補版本。
- Debian/darktable—升級至 1.6.7-1 或更新版本
- Debian/dcraw—升級至 9.26-1 或更新版本
- Debian/exactimage—升級至 0.9.1-5 或更新版本
- Debian/exactimage—升級至 0.8.1-3+deb6u4 或更新版本
- —升級至 3.15.4-6 或更新版本
- —升級至 3.15.4-4.2+deb8u1 或更新版本
- —升級至 16.0+dfsg1-1 或更新版本
- —升級至 0.16.2-1 或更新版本
- —升級至 0.9.1-1+deb6u1 或更新版本
- —升級至 4.2-2 或更新版本
CVE-2015-3885 正在被利用嗎?
中等 — EPSS 為 5.4%,可持續追蹤但非最高優先。
受影響套件(10)
- from 0, < 1.6.7-1
- from 0, < 9.26-1
- from 0, < 0.9.1-5
- from 0, < 0.8.1-3+deb6u4
- from 0, < 3.15.4-6
- from 0, < 3.15.4-4.2+deb8u1
- from 0, < 16.0+dfsg1-1
- from 0, < 0.16.2-1
- from 0, < 0.9.1-1+deb6u1
- from 0, < 4.2-2