Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
| Software | From | Fixed in |
|---|---|---|
| dcraw_project / dcraw | - | 7.00.x |
| fedoraproject / fedora | 21 | 21.x |