Advisories ยป MGASA-2014-0050

Updated darktable package fixes two vulnerabilities

Publication date: 10 Feb 2014
Modification date: 10 Feb 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1438 , CVE-2013-1439

Description

Updated darktable package fixes security vulnerabilities:

Darktable before version 1.2.3 contains an embedded copy of LibRaw that
incorrectly handled photo files. If a user was tricked into processing a
specially crafted photo file, darktable could be made to crash, resulting
in a denial of service (CVE-2013-1438, CVE-2013-1439).
                

References

SRPMS

3/core