There is a floating point exception in dcraw_common.cpp of libRAW. It will lead to remote denial of service attack. This code is embedded in rawtherapee (CVE-2017-13735). References: . MGASA-2021-0004 - Updated rawtherapee package fixes a security vulnerability Publication date: 04 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0004.html Type: security Affected Mageia releases: 7 CVE: CVE-2017-13735 There is a floating point exception in dcraw_common.cpp of libRAW. It will lead to remote denial of service attack. This code is embedded in rawtherapee (CVE-2017-13735). References: - https://bugs.mageia.org/show_bug.cgi?id=27963 - https://lists.fedoraproject.org/archives/list/
Security fix for CVE-2017-13735. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-8aad495d9b 2017-09-30 05:57:53.235940 --------------------------------------------------------------------------------Name : rawtherapee Product : Fedora 27 Version : 5.2 Release : 2.fc27 URL : http://www.rawtherapee.com/ Summary : Raw image processing software Description : Rawtherapee is a RAW image processing software. It gives full control over many parameters to enhance the raw picture before finally exporting it to some common image format. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-13735 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade rawtherapee' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-13735. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-b10e1a9166 2017-09-19 20:01:33.116723 --------------------------------------------------------------------------------Name : rawtherapee Product : Fedora 26 Version : 5.2 Release : 2.fc26 URL : http://www.rawtherapee.com/ Summary : Raw image processing software Description : Rawtherapee is a RAW image processing software. It gives full control over many parameters to enhance the raw picture before finally exporting it to some common image format. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-13735 --------------------------------------------------------------------------------References: [ 1 ] Bug #1488930 - CVE-2017-13735 rawtherapee: libraw: Floating point exception in kodak_radc_load_raw function in internal/dcraw_common.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1488930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade rawtherapee' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2015-3885 (dcraw input sanitization), bz #1221257. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8187 2015-05-14 20:19:25 -------------------------------------------------------------------------------- Name : rawtherapee Product : Fedora 22 Version : 4.2 Release : 9.fc22 URL : http://www.rawtherapee.com/ Summary : Raw image processing software Description : Rawtherapee is a RAW image processing software. It gives full control over many parameters to enhance the raw picture before finally exporting it to some common image format. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-3885 (dcraw input sanitization), bz #1221257 -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2015 Matthew Miller - 4.2-9 - Security fix for CVE-2015-3885 (dcraw input sanitization), bz #1221257 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1221257 - CVE-2015-3885 rawtherapee: dcraw: input sanitization flaw leading to buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1221257 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rawtherapee' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.