MGASA-2017-0359

Source
https://advisories.mageia.org/MGASA-2017-0359.html
Import Source
https://advisories.mageia.org/MGASA-2017-0359.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0359
Related
Published
2017-10-05T20:37:56Z
Modified
2017-10-05T20:15:44Z
Summary
Updated rawtherapee packages fix security vulnerabilities
Details

It was discovered that rawtherapee had a floating point exception in the kodakradcload_raw function in dcraw.cc (CVE-2017-13735).

It was discovered that rawtherapee had a Heap-based 1 byte buffer overflow in the processCanonCameraInfo function in dcraw.c (CVE-2017-14348).

It was discovered that rawtherapee had a Stack Buffer Overflow in xtrans_interpolate in dcraw.c that could allow a remote denial of service and code execution attack (CVE-2017-14265).

References
Credits

Affected packages

Mageia:6 / rawtherapee

Package

Name
rawtherapee
Purl
pkg:rpm/mageia/rawtherapee?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1-1.2.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / rawtherapee

Package

Name
rawtherapee
Purl
pkg:rpm/mageia/rawtherapee?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1-4.2.mga5

Ecosystem specific

{
    "section": "core"
}