Vulnerability Description
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dcraw Project | Dcraw | 9.28-2 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=984761ExploitIssue TrackingThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=984761ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-3624?
CVE-2021-3624 is a vulnerability with a CVSS score of 7.8 (HIGH). There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.
How severe is CVE-2021-3624?
CVE-2021-3624 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3624?
Check the references section above for vendor advisories and patch information. Affected products include: Dcraw Project Dcraw, Debian Debian Linux.