CVE-2020-24890
16.09.2020, 15:15
libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain wayEnginsight
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 0.20.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||
| dcraw |
| ||||||||
| exactimage |
| ||||||||
| kodi |
| ||||||||
| libraw |
| ||||||||
| rawtherapee |
| ||||||||
| ufraw |
| ||||||||
| xbmc |
|
Common Weakness Enumeration
References