Updated dcraw and ufraw package fix security vulnerability
Publication date: 17 Jan 2014Modification date: 17 Jan 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1438
Description
Due to flaws in the embedded copy of LibRaw in dcraw and ufraw, corrupt input files might trigger a division by zero, an infinite loop, or a null pointer dereference (CVE-2013-1438). The dcraw and ufraw packages have been updated to their newest versions and patched to fix the flaws in the embedded LibRaw library. They have also been patched to use the more secure lcms2 color management library, rather than the unmaintained lcms library.
References
SRPMS
3/core
- dcraw-9.19-1.mga3
- ufraw-0.19.2-5.mga3