oss-sec mailing list archives
Re: Re: Crashes and memory safety bugs in dcraw
From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Fri, 23 Nov 2018 19:33:55 -0600 (CST)
On Fri, 23 Nov 2018, Ian Zimmerman wrote:
An important side note: because dcraw intentionally doesn't provide a library, only an executable, code from it is bundled in at least some applications that use it; thus updating the dcraw package in a distro will not by itself be the end of this problem for the distro. One such application : RawTherapee
GraphicsMagick also bundles some version of dcraw for its Microsoft Windows builds. It is executed as an external program so if it becomes corrupted, it will not corrupt the invoking application.
Another consideration is that the dcraw author has huge sample image archive that he is only willing to sell for private use. This means that other projects (including those which derived code from dcraw) might not work correctly with as many input files since they have not done as much validation.
Bob -- Bob Friesenhahn bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/ Public Key, http://www.simplesystems.org/users/bfriesen/public-key.txt
Current thread:
- Crashes and memory safety bugs in dcraw Hanno Böck (Nov 23)
- Re: Crashes and memory safety bugs in dcraw Agostino Sarubbo (Nov 23)
- Re: Crashes and memory safety bugs in dcraw Hanno Böck (Nov 23)
- Re: Crashes and memory safety bugs in dcraw Marcus Meissner (Nov 23)
- Re: Crashes and memory safety bugs in dcraw Ian Zimmerman (Nov 23)
- Re: Re: Crashes and memory safety bugs in dcraw Bob Friesenhahn (Nov 23)
- Re: Crashes and memory safety bugs in dcraw Marcus Meissner (Nov 27)
- Re: Crashes and memory safety bugs in dcraw Agostino Sarubbo (Nov 23)