Bugzilla – Bug 823114
VUL-0: darktable: CVE-2013-2126: double-free issue in embed copy of libraw
Last modified: 2015-02-19 01:20:06 UTC
The darktable has an embedded copy of libraw. A security incident for libraw was started in bnc#822665.
bugbot adjusting priority
Based on the discussion of the topic in darktable-devel mailinglist [1] darktable is not vulnarable as the libraw in darktable is not updated to 15.0+ [1] http://tinyurl.com/kj46jcg
If I'm not mistaken the affected libraw lines were introduced with commit 1a8e92ff, and that was actually part of 0.14.0. I'll try to verify this with the libraw guys.
Hi, On the darktable-devel list it was mentioned that the c14ae38 commit of the libraw (0.14-stable branch) has been integrated to darktarble. If that solves the security bug I will backport the patch for our darktable packages
Sorry, I couldn't find commit c14ae38 inside the 0.14-stable branch. What I found was commit c14ae36, so maybe it was just a typo. ... Yes, it was a typo. :) +2013-05-31 Alex Tutubalin <lexa@lexa.ru> + * Fixed double call to free() on broken legacy-layout images + (backport from 0.15.x) So from my point of view it should be sufficient if you could backport that patch to our darktable package.
Ooops sorry for the typo. I will fix darktable
Changed needinfo to our security-team.
This is an autogenerated message for OBS integration: This bug (823114) was mentioned in https://build.opensuse.org/request/show/178381 Maintenance /
This is an autogenerated message for OBS integration: This bug (823114) was mentioned in https://build.opensuse.org/request/show/178389 Factory / darktable
Togan, please include the CVE number inside the changes file and resubmit.
done sr#178409
This is an autogenerated message for OBS integration: This bug (823114) was mentioned in https://build.opensuse.org/request/show/178409 Maintenance /
With the factory request mentioned in Comment 12 the issue should be resolved
Looks good to me. Reassigning to security-team. openSUSE 12.2 and 12.3 updates will be released soon.
openSUSE-SU-2013:1083-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 823114 CVE References: CVE-2013-2126 Sources used: openSUSE 12.3 (src): darktable-1.1.3-1.5.3, darktable-1.1.3-1.5.4 openSUSE 12.2 (src): darktable-1.0.5-3.9.3