{"id":"MGASA-2014-0011","summary":"Updated dcraw and ufraw package fix security vulnerability","details":"Due to flaws in the embedded copy of LibRaw in dcraw and ufraw, corrupt\ninput files might trigger a division by zero, an infinite loop, or a null\npointer dereference (CVE-2013-1438).\n\nThe dcraw and ufraw packages have been updated to their newest versions\nand patched to fix the flaws in the embedded LibRaw library.  They have\nalso been patched to use the more secure lcms2 color management library,\nrather than the unmaintained lcms library.\n","modified":"2026-04-16T06:24:51.835718964Z","published":"2014-01-17T00:24:49Z","upstream":["CVE-2013-1438"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0011.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12125"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2013-December/124176.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2013-December/124183.html"}],"affected":[{"package":{"name":"dcraw","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/dcraw?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.19-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0011.json"}},{"package":{"name":"ufraw","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/ufraw?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.19.2-5.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0011.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}