Menu

#396 patch for CVE-2015-3885: don't write past array boundaries

closed-fixed
nobody
None
5
2015-05-22
2015-05-21
No

Hi there,

the attached patch fixes the vulnerability CVE-2015-3885 which made the function ljpeg_start() in dcraw (and all programs using the affected code) susceptible to writing long past the end of the array data if the length field in the header of the file was smaller than 2.

The patch is basically identical to the one I submitted for dcraw.

1 Attachments

Discussion

  • Niels Kristian Bech Jensen

    • status: open --> closed-fixed
     
  • Niels Kristian Bech Jensen

    Hi Nils.

    Thank you for the report and patch. I have commited it to the cvs repository.

    Regards,
    Niels Kristian

     

Log in to post a comment.

MongoDB Logo MongoDB