CVE-2020-15503
02.07.2020, 14:15
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.Enginsight
Vendor | Product | Version |
---|---|---|
libraw | libraw | 𝑥 ≤ 0.19.5 |
libraw | libraw | 0.20:beta1 |
libraw | libraw | 0.20:beta2 |
libraw | libraw | 0.20:beta3 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
darktable |
| ||||||||||||||||||||||||||
dcraw |
| ||||||||||||||||||||||||||
exactimage |
| ||||||||||||||||||||||||||
kodi |
| ||||||||||||||||||||||||||
libraw |
| ||||||||||||||||||||||||||
rawtherapee |
| ||||||||||||||||||||||||||
ufraw |
| ||||||||||||||||||||||||||
xbmc |
|
Common Weakness Enumeration
References