PT-2020-6397 · Libraw+5 · Libraw+5

Sleicasper

·

Published

2020-08-19

·

Updated

2022-12-09

·

CVE-2020-24870

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libraw versions prior to 0.20.1
Description The issue is related to a stack buffer overflow in the LibRaw::identify process dng fields function within the identify.cpp component of the Libraw image processing library. This overflow can be exploited by a remote attacker to gain access to confidential data, compromise data integrity, and cause a denial of service.
Recommendations For versions prior to 0.20.1, update to version 0.20.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the LibRaw::identify process dng fields function in identify.cpp until a patch is applied.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2021:4381
ALT-PU-2020-3199
BDU:2021-04597
CESA-2021_4381
CVE-2020-24870
RHSA-2021:4381
RHSA-2021_4381
RLSA-2021:4381

Affected Products

Alt Linux
Almalinux
Centos
Libraw
Red Hat
Rocky Linux