Denial of service - CVE-2015-3885

 

Denial of service - CVE-2015-3885

Published: October 17, 2016


Vulnerability identifier: #VU1004
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3885
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause DoS condition on the target system.
The weakness exists due to buffer overflow caused by processing of malformed XMP or RAW image and allowing attackers to trigger the affected service deny or execute arbitrary code.
Successful exploitation of the vulnerability results in denial of service or arbitrary code execution on the vulnerable system.

Affected software

Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
Fedora
libraw-devel-static
libraw-devel
mingw-LibRaw
LibRaw
ufraw
rawstudio
rawtherapee
dcraw

How to mitigate CVE-2015-3885

Update stable distribution (jessie) to 3.15.4-4.2+deb8u1.

Update testing distribution (stretch) to 3.17.0+ds1-3.

Update unstable distribution (sid) to3.17.0+ds1-3.


libraw-devel-static - update to 0.15.4-45.1
libraw-devel - update to 0.15.4-45.1
mingw-LibRaw - addressed in versions 0.16.1-1.fc21, 0.16.1-1.fc22, 0.16.2-1.fc21, 0.16.2-1.fc22
LibRaw - addressed in versions 0.16.1-6.fc21, 0.16.2-1.fc21, 0.16.2-1.fc22
ufraw - addressed in versions 0.21-1.fc21, 0.21-1.fc22
rawstudio - update to 2.1-0.1.20150511git983bda1.fc21
rawtherapee - update to 4.2-9.fc22
dcraw - addressed in versions 9.25.0-2.fc21, 9.25.0-2.fc22

External References

Related Security Bulletins