CVE-2020-24890
EUVD-2020-1759816.09.2020, 15:15
libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain wayEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libraw | libraw | 0.20.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| darktable |
| ||||||||
| dcraw |
| ||||||||
| exactimage |
| ||||||||
| kodi |
| ||||||||
| libraw |
| ||||||||
| rawtherapee |
| ||||||||
| ufraw |
| ||||||||
| xbmc |
|
Common Weakness Enumeration
References