Advisories ยป MGASA-2014-0011

Updated dcraw and ufraw package fix security vulnerability

Publication date: 17 Jan 2014
Modification date: 17 Jan 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1438

Description

Due to flaws in the embedded copy of LibRaw in dcraw and ufraw, corrupt
input files might trigger a division by zero, an infinite loop, or a null
pointer dereference (CVE-2013-1438).

The dcraw and ufraw packages have been updated to their newest versions
and patched to fix the flaws in the embedded LibRaw library.  They have
also been patched to use the more secure lcms2 color management library,
rather than the unmaintained lcms library.
                

References

SRPMS

3/core