Bug#1087911: Memory leaks in dcraw

2025-03-03 Thread Filip Hroch
Dear Colleagues, I have investigated and fixed the issue: * Below is cited an instance of the desired behaviour, and the reason, why I wrote wrappers of fseek() and similar (introduced in Debian's version 9.28-3). The procedure finish by exit(1), and indicates of a fail. In this case, t

Bug#1087911: [Debian-astro-maintainers] Bug#1087911: Memory leaks in dcraw

2024-11-21 Thread Thorsten Alteholz
Control: severity -1 normal On 20.11.24 06:28, Ajin Deepak wrote: Found a memory leak in the latest version of dcraw. Did you already apply for a CVE number? Impact: Memory leaks can create vulnerabilities. Attackers might exploit them to degrade service (denial of service attacks) or in

Bug#1087911: Memory leaks in dcraw

2024-11-19 Thread Ajin Deepak
Package: dcraw Version: 9.28-7 Found a memory leak in the latest version of dcraw. Here is a transcript: osboxes@osboxes:~/Desktop$ dcraw -g 2.2 1.0 -b 1.2 -j leak fseek(0x5a1841ba9430, -2145648639,0): Invalid argument osboxes@osboxes:~/Desktop$ For reference: https://cve.mitre.org/cgi-bin/cveke