CVE-2013-1441

medium
Published 2013-09-16 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.8.9-2
debian debianbullseyefixed0.8.9-2
debian debianforkyfixed0.8.9-2
debian debiansidfixed0.8.9-2
debian debiantrixiefixed0.8.9-2

Application impact

VendorProductVersionsFixed
exactcodeexactimage{"endIncluding":"0.8.9"}
exactcodeexactimage0.0.1
exactcodeexactimage0.0.2
exactcodeexactimage0.0.3
exactcodeexactimage0.0.4
exactcodeexactimage0.0.5
exactcodeexactimage0.0.6
exactcodeexactimage0.0.7
exactcodeexactimage0.0.8
exactcodeexactimage0.0.9
exactcodeexactimage0.0.10
exactcodeexactimage0.0.11
exactcodeexactimage0.0.12
exactcodeexactimage0.0.13
exactcodeexactimage0.0.14
exactcodeexactimage0.0.15
exactcodeexactimage0.0.16
exactcodeexactimage0.0.17
exactcodeexactimage0.1.0
exactcodeexactimage0.2.0
exactcodeexactimage0.2.1
exactcodeexactimage0.2.2
exactcodeexactimage0.2.3
exactcodeexactimage0.2.4
exactcodeexactimage0.2.5
exactcodeexactimage0.2.6
exactcodeexactimage0.3.0
exactcodeexactimage0.3.1
exactcodeexactimage0.3.2
exactcodeexactimage0.3.3
exactcodeexactimage0.3.4
exactcodeexactimage0.3.5
exactcodeexactimage0.3.6
exactcodeexactimage0.3.7
exactcodeexactimage0.3.8
exactcodeexactimage0.4.0
exactcodeexactimage0.4.1
exactcodeexactimage0.4.2
exactcodeexactimage0.5.0
exactcodeexactimage0.5.1
exactcodeexactimage0.5.2
exactcodeexactimage0.5.3
exactcodeexactimage0.6.0
exactcodeexactimage0.6.1
exactcodeexactimage0.6.2
exactcodeexactimage0.6.3
exactcodeexactimage0.6.4
exactcodeexactimage0.6.5
exactcodeexactimage0.6.6
exactcodeexactimage0.6.7
exactcodeexactimage0.6.8
exactcodeexactimage0.6.9
exactcodeexactimage0.7.0
exactcodeexactimage0.7.1
exactcodeexactimage0.7.2
exactcodeexactimage0.7.3
exactcodeexactimage0.7.4
exactcodeexactimage0.7.5
exactcodeexactimage0.7.6
exactcodeexactimage0.8.0
exactcodeexactimage0.8.1
exactcodeexactimage0.8.2
exactcodeexactimage0.8.3
exactcodeexactimage0.8.4
exactcodeexactimage0.8.5
exactcodeexactimage0.8.6
exactcodeexactimage0.8.7
exactcodeexactimage0.8.8

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.