CVE-2020-15503
02.07.2020, 14:15
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 𝑥 ≤ 0.19.5 |
| libraw | libraw | 0.20:beta1 |
| libraw | libraw | 0.20:beta2 |
| libraw | libraw | 0.20:beta3 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||||||||||||||||||||
| dcraw |
| ||||||||||||||||||||||||||
| exactimage |
| ||||||||||||||||||||||||||
| kodi |
| ||||||||||||||||||||||||||
| libraw |
| ||||||||||||||||||||||||||
| rawtherapee |
| ||||||||||||||||||||||||||
| ufraw |
| ||||||||||||||||||||||||||
| xbmc |
|
Common Weakness Enumeration
References