Open CVEs in libkdcraw

Bug #1193065 reported by Scott Kitterman
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libkdcraw (Ubuntu)
Fix Released
High
Scott Kitterman
Precise
Fix Released
High
Unassigned
Quantal
Fix Released
High
Unassigned
Raring
Fix Released
High
Unassigned
Saucy
Fix Released
High
Scott Kitterman

Bug Description

CVE-2013-2126/7 need fixing

2127 is raring/saucy only

Revision history for this message
Scott Kitterman (kitterman) wrote :

Fixed in precise, see USN-1885-1.

information type: Public → Public Security
Changed in libkdcraw (Ubuntu Precise):
importance: Undecided → High
status: New → Fix Released
Revision history for this message
Scott Kitterman (kitterman) wrote :
Revision history for this message
Scott Kitterman (kitterman) wrote :
Changed in libkdcraw (Ubuntu Quantal):
status: New → In Progress
Changed in libkdcraw (Ubuntu Raring):
status: New → In Progress
Changed in libkdcraw (Ubuntu Quantal):
importance: Undecided → High
Changed in libkdcraw (Ubuntu Raring):
importance: Undecided → High
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

ACK on the debdiffs. Thanks!

Changed in libkdcraw (Ubuntu Quantal):
status: In Progress → Fix Committed
Changed in libkdcraw (Ubuntu Raring):
status: In Progress → Fix Committed
Revision history for this message
Scott Kitterman (kitterman) wrote :

Fix uploaded for saucy.

Changed in libkdcraw (Ubuntu Saucy):
importance: Undecided → High
assignee: nobody → Scott Kitterman (kitterman)
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package libkdcraw - 4:4.10.4-0ubuntu2

---------------
libkdcraw (4:4.10.4-0ubuntu2) saucy; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution via
    broken full-color images and a buffer overflow (LP: #1193065)
    - debian/patches/CVE2013-2126.diff: fix error handling in
      libraw/src/libraw_cxx.cpp.
    - CVE-2013-2126
    - debian/patches/CVE2013-2127.diff: fix wrong data_maximum calcluation
      in libraw/src/libraw_cxx.cpp.
    - CVE-2013-2127
 -- Scott Kitterman <email address hidden> Thu, 20 Jun 2013 15:54:44 -0400

Changed in libkdcraw (Ubuntu Saucy):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package libkdcraw - 4:4.10.2-0ubuntu1.1

---------------
libkdcraw (4:4.10.2-0ubuntu1.1) raring-security; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution via
    broken full-color images and a buffer overflow (LP: #1193065)
    - debian/patches/CVE2013-2126.diff: fix error handling in
      libraw/src/libraw_cxx.cpp.
    - CVE-2013-2126
    - debian/patches/CVE2013-2127.diff: fix wrong data_maximum calcluation
      in libraw/src/libraw_cxx.cpp.
    - CVE-2013-2127
 -- Scott Kitterman <email address hidden> Thu, 20 Jun 2013 15:38:37 -0400

Changed in libkdcraw (Ubuntu Raring):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package libkdcraw - 4:4.9.2-0ubuntu1.1

---------------
libkdcraw (4:4.9.2-0ubuntu1.1) quantal-security; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution via
    broken full-color images (LP: #1193065)
    - debian/patches/CVE-2013-2126: fix error handling in
      libraw/src/libraw_cxx.cpp.
    - CVE-2013-2126
 -- Scott Kitterman <email address hidden> Thu, 20 Jun 2013 14:02:00 -0400

Changed in libkdcraw (Ubuntu Quantal):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.