Vulnerabilities > CVE-2013-2126 - Resource Management Errors vulnerability in multiple products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
libraw
canonical
opensuse
CWE-399
nessus

Summary

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-13112.NASL
    descriptionKDE released updates for its Workspaces, Applications, and Development Platform. These updates are the last in a series of monthly stabilization updates to the 4.10 series. 4.10.5 updates bring many bugfixes on top of the latest edition in the 4.10 series and are recommended updates for everyone running 4.10.4 or earlier versions. See also: http://kde.org/announcements/announce-4.10.5.php Fix for CVE-2013-2126, double-free flaw when handling damaged full-color in Foveon and sRAW files Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-07-24
    plugin id69027
    published2013-07-24
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/69027
    titleFedora 18 : analitza-4.10.5-1.fc18 / ark-4.10.5-1.fc18 / audiocd-kio-4.10.5-1.fc18 / etc (2013-13112)
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-1885-1.NASL
    descriptionIt was discovered that libKDcraw incorrectly handled broken full-color images. If a user or automated system were tricked into processing a specially crafted raw image, applications linked against libKDcraw could be made to crash, resulting in a denial of service, or possibly execute arbitrary code. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id66923
    published2013-06-19
    reporterUbuntu Security Notice (C) 2013-2019 Canonical, Inc. / NASL script (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/66923
    titleUbuntu 12.04 LTS : libkdcraw vulnerability (USN-1885-1)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-9798.NASL
    descriptionFix for CVE-2013-2126, double-free flaw when handling damaged full-color in Foveon and sRAW files. Latest upstream, corrects gcc 4.8 issues. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-07-12
    plugin id67383
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/67383
    titleFedora 17 : LibRaw-0.14.8-2.fc17 (2013-9798)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2013-538.NASL
    descriptionThis update of darktable fixes a problem inside the embedded libraw version. - Fix for CVE-2013-2126 - added backported patch from git master 0001-fixed-error-handling-for-broken-full-color-images.p atch fixes bnc#823114-
    last seen2020-06-05
    modified2014-06-13
    plugin id75060
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75060
    titleopenSUSE Security Update : darktable (openSUSE-SU-2013:1083-1)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201309-09.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201309-09 (LibRaw, libkdcraw: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in LibRaw and libkdcraw. Please review the CVE identifiers referenced below for details. Impact : A remote attacker could entice a user to open a specially crafted file, possibly resulting in arbitrary code execution or Denial of Service. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id69900
    published2013-09-15
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/69900
    titleGLSA-201309-09 : LibRaw, libkdcraw: Multiple vulnerabilities
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-1884-1.NASL
    descriptionIt was discovered that LibRaw incorrectly handled broken full-color images. If a user or automated system were tricked into processing a specially crafted raw image, applications linked against LibRaw could be made to crash, resulting in a denial of service, or possibly execute arbitrary code. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id66922
    published2013-06-19
    reporterUbuntu Security Notice (C) 2013-2019 Canonical, Inc. / NASL script (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/66922
    titleUbuntu 12.04 LTS / 12.10 / 13.04 : libraw vulnerability (USN-1884-1)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-13499.NASL
    descriptionKDE released updates for its Workspaces, Applications, and Development Platform. These updates are the last in a series of monthly stabilization updates to the 4.10 series. 4.10.5 updates bring many bugfixes on top of the latest edition in the 4.10 series and are recommended updates for everyone running 4.10.4 or earlier versions. See also: http://kde.org/announcements/announce-4.10.5.php Fix for CVE-2013-2126, double-free flaw when handling damaged full-color in Foveon and sRAW files Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-07-31
    plugin id69153
    published2013-07-31
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/69153
    titleFedora 17 : analitza-4.10.5-1.fc17 / ark-4.10.5-1.fc17 / audiocd-kio-4.10.5-1.fc17 / etc (2013-13499)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-9773.NASL
    descriptionFix for CVE-2013-2126, double-free flaw when handling damaged full-color in Foveon and sRAW files. Latest upstream, corrects gcc 4.8 issues. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-07-12
    plugin id67377
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/67377
    titleFedora 18 : LibRaw-0.14.8-2.fc18 (2013-9773)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2013-567.NASL
    descriptionlibkdcraw was updated to fix a possible double-free() on error recovery on damaged full-color (Foveon, sRAW) files. (CVE-2013-2126)
    last seen2020-06-05
    modified2014-06-13
    plugin id75078
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75078
    titleopenSUSE Security Update : libkdcraw (openSUSE-SU-2013:1168-1)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-13038.NASL
    descriptionFix for CVE-2013-2126, double-free flaw when handling damaged full-color in Foveon and sRAW files Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-07-24
    plugin id69026
    published2013-07-24
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/69026
    titleFedora 19 : libkdcraw-4.10.5-2.fc19 (2013-13038)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-9722.NASL
    descriptionFix for CVE-2013-2126, double-free flaw when handling damaged full-color in Foveon and sRAW files. Latest upstream, corrects gcc 4.8 issues. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-17
    modified2013-07-12
    plugin id67373
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/67373
    titleFedora 19 : LibRaw-0.14.8-2.fc19 (2013-9722)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2013-537.NASL
    descriptionThis update of libraw fixes a security issue. - security update : - CVE-2013-2126.patch [bnc#822665]
    last seen2020-06-05
    modified2014-06-13
    plugin id75059
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75059
    titleopenSUSE Security Update : libraw (openSUSE-SU-2013:1085-1)