// For flags

CVE-2013-1438

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.

Vulnerabilidad no especificada en dcraw 0.8.x hasta 0.8.9, utilizado en libraw, ufraw, shotwell y otros productos, permite a atacantes dependientes de contexto causar una denegación de servicio a través de un archivo fotográfico manipulado que desencadena un (1) divide-by-zero, (2) bucle infinito, o (3) referencia a puntero nulo.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-01-26 CVE Reserved
  • 2013-09-02 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.0
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.0"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.1
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.1"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.2
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.2"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.3
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.3"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.4
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.4"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.5
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.5"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.6
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.6"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.7
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.7"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.8
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.8"
-
Affected
Dave Coffin
Search vendor "Dave Coffin"
Dcraw
Search vendor "Dave Coffin" for product "Dcraw"
0.8.9
Search vendor "Dave Coffin" for product "Dcraw" and version "0.8.9"
-
Affected