CVE-2015-3885

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dcraw_project:dcraw:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-05-19 18:59

Updated : 2024-02-04 18:53


NVD link : CVE-2015-3885

Mitre link : CVE-2015-3885

CVE.ORG link : CVE-2015-3885


JSON object : View

Products Affected

dcraw_project

  • dcraw

fedoraproject

  • fedora
CWE
CWE-189

Numeric Errors