| Name | CVE-2013-1438 |
| Description | Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-2748-1 |
| Debian Bugs | 721231, 721232, 721233, 721234, 721235, 721236, 721237 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| darktable (PTS) | bullseye | 3.4.1-5 | fixed |
| bookworm | 4.2.1-4 | fixed | |
| trixie | 5.0.1-2 | fixed | |
| forky, sid | 5.2.1-1 | fixed | |
| dcraw (PTS) | bullseye | 9.28-2 | fixed |
| bookworm | 9.28-3 | fixed | |
| forky, sid, trixie | 9.28-8 | fixed | |
| exactimage (PTS) | bullseye | 1.0.2-8 | fixed |
| bookworm | 1.0.2-11 | fixed | |
| forky, sid, trixie | 1.2.1-2 | fixed | |
| libkdcraw (PTS) | forky, sid, trixie | 25.04.0-1 | fixed |
| libraw (PTS) | bullseye | 0.20.2-1+deb11u1 | fixed |
| bullseye (security) | 0.20.2-1+deb11u2 | fixed | |
| bookworm | 0.20.2-2.1+deb12u1 | fixed | |
| forky, sid, trixie | 0.21.4-2 | fixed | |
| rawtherapee (PTS) | bullseye | 5.8-3 | fixed |
| bookworm | 5.9-1 | fixed | |
| trixie | 5.11-2 | fixed | |
| forky, sid | 5.12-2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| darktable | source | wheezy | 1.0.4-1+deb7u2 | |||
| darktable | source | (unstable) | 1.2.2-2 | 721233 | ||
| dcraw | source | (unstable) | 9.28-1 | unimportant | 721232 | |
| exactimage | source | squeeze | 0.8.1-3+deb6u2 | DSA-2748-1 | ||
| exactimage | source | wheezy | 0.8.5-5+deb7u2 | DSA-2748-1 | ||
| exactimage | source | (unstable) | 0.8.9-1 | 721236 | ||
| libkdcraw | source | (unstable) | 24.12.0-1 | |||
| libraw | source | (unstable) | 0.15.4-1 | 721231 | ||
| rawstudio | source | (unstable) | (unfixed) | unimportant | 721237 | |
| rawtherapee | source | (unstable) | (not affected) | |||
| ufraw | source | (unstable) | 0.19.2-2 | 721234 | ||
| xbmc | source | (unstable) | 2:13.2+dfsg1-5 | unimportant | 721235 |
[wheezy] - libraw <no-dsa> (Minor issue)
[squeeze] - libraw <no-dsa> (Minor issue)
[wheezy] - libkdcraw <no-dsa> (Minor issue)
[wheezy] - ufraw <no-dsa> (end-user app)
[squeeze] - ufraw <no-dsa> (end-user app)
- rawtherapee <not-affected> (unimportant; bug #721238)
Starting with 2:13.2+dfsg1-5 xbmc is a transitional package
Back in 2013, libkdcraw was fixed in 4:4.10.5-2 and later on removed and then
re-introduced in sid without the epoch, so now marking 24.12.0-1 as the first
upload to sid as the new fixed version, current libkdcraw uses the system-wide libraw