PT-2020-6705 · Leptonica+2 · Leptonica+2

Published

2020-03-12

·

Updated

2024-12-19

·

CVE-2020-36280

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Leptonica versions prior to 1.80.0
Description The issue is related to a heap-based buffer over-read in the pixReadFromTiffStream function, which is connected to the tiffio.c component. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 1.80.0, update to version 1.80.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pixReadFromTiffStream function until a patch is available.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3559
ALT-PU-2022-1147
ALT-PU-2024-16902
BDU:2022-05686
CVE-2020-36280
MGASA-2021-0290
OESA-2021-1327

Affected Products

Alt Linux
Astra Linux
Leptonica