CVE-2020-15503
02.07.2020, 14:15
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 𝑥 ≤ 0.19.5 |
| libraw | libraw | 0.20:beta1 |
| libraw | libraw | 0.20:beta2 |
| libraw | libraw | 0.20:beta3 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||||||||||||||||||||
| dcraw |
| ||||||||||||||||||||||||||
| exactimage |
| ||||||||||||||||||||||||||
| kodi |
| ||||||||||||||||||||||||||
| libraw |
| ||||||||||||||||||||||||||
| rawtherapee |
| ||||||||||||||||||||||||||
| ufraw |
| ||||||||||||||||||||||||||
| xbmc |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libraw-devel |
| ||||||||||||||||||||||||||||||||
| libraw16 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| LibRaw |
| ||
| LibRaw-devel |
| ||
| gnome-settings-daemon |
| ||
| webkit2gtk3 |
| ||
| webkit2gtk3-devel |
| ||
| webkit2gtk3-jsc |
| ||
| webkit2gtk3-jsc-devel |
|
Common Weakness Enumeration
References