Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
dcraw 缓冲区错误漏洞
Vulnerability Description
dcraw是美国软件开发者David J. Coffin所研发的一套开源的用于把相机拍的RAW片转换成PPM或者TIFF格式的图片的工具。 dcraw 9.28及之前版本(使用在ufraw-batch和其他设备)中的‘find_green()’函数存在基于栈的缓冲区溢出漏洞。远程攻击者可借助恶意制作的raw图片文件利用该漏洞劫持控制流或造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A