Summary
Several denial-of-service vulnerabilities were discovered in the dcraw code base, a program for procesing raw format images from digital cameras. This update corrects them in the copy that is embedded in the exactimage package.
Solution
For the oldstable distribution (squeeze), this problem has been fixed in version 0.8.1-3+deb6u2.
For the stable distribution (wheezy), this problem has been fixed in version 0.8.5-5+deb7u2.
For the unstable distribution (sid), this problem has been fixed in version 0.8.9-1.
We recommend that you upgrade your exactimage packages.
Insight
ExactImage is a fast C++ image processing library. Unlike many other library frameworks it allows operation in several color spaces and bit depths natively, resulting in low memory and computational requirements.
Affected
exactimage on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-1438 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities