CVE-2013-2126

high
Published 2013-08-14 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-2126

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/53888

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/53883

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/53547

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.2.1-2
debian debianbullseyefixed1.2.1-2
debian debianforkyfixed1.2.1-2
debian debiansidfixed1.2.1-2
debian debiantrixiefixed1.2.1-2
ubuntu ubuntu12.04affected
ubuntu ubuntu12.10affected
ubuntu ubuntu13.04affected
suse suse12.2affected
suse suse12.3affected

Application impact

VendorProductVersionsFixed
librawlibraw{"endIncluding":"0.15.1"}
librawlibraw0.15.0

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.