LibRaw 0.15.1 notes the following fix :
* check for possible buffer overrun in exposure correction code
Successful exploitation could allow for the execution of arbitrary code with the privileges of the user running an application linked to LibRaw.
This has been fixed in LibRaw 0.15.1 .
Created LibRaw tracking bugs for this issue
Affects: fedora-all [bug 968387]
This seems to affect 0.15.x branch only, we ship only 0.14.x currently. Can you verify?
This has been assigned CVE-2013-2127 as per:
This one I cannot tell by looking at the code whether or not we are affected. I'm going to email upstream and ask.
According to upstream, 0.14.x is not affected by this flaw:
"0.14.x are not affected by 'buffer overrun' (this is not arbitrary access in 0.15 , but access to lookup table at fixed index [(unsigned)(-1)] )
The code calculating max real data value is completely different in 0.14 (and early 0.15 alphas), so no prior initialization of data maximum to -1."
Since we only ship 0.14.x, this does not affect Fedora at all.
Digikam embeds 0.15.0.beta3 and this patch applies to it, so it needs to be updated.
Created libkdcraw tracking bugs for this issue
Affects: fedora-all [bug 970713]