Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gtt1995

#33439of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2021-7867
7.8
2021-04-12
Libraw · Libraw · CVE-2021-32142
**Name of the Vulnerable Software and Affected Versions** LibRaw version 0.20.0 **Description** The issue is related to a buffer overflow in the `LibRaw buffer datastream::gets` function, located in the `libraw datastream.cpp` component of the LibRaw image processing library. This allows an attacker to access confidential data, compromise its integrity, and cause a denial of service using a specially crafted file. The vulnerability can be exploited to escalate privileges. **Recommendations** For LibRaw version 0.20.0, consider disabling the `LibRaw buffer datastream::gets` function as a temporary workaround until a patch is available. Restrict access to the `libraw datastream.cpp` component to minimize the risk of exploitation. Avoid using the `gets` function in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.