CVE-2018-20363: Null Pointer Dereference
Last updated 11 July 2025
Other sources
LibRaw::raw2image in librawcxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20363?
CVE-2018-20363 is a vulnerability in LibRaw 0.19.1 that allows for a NULL pointer dereference in LibRaw::raw2image.
What is the severity of CVE-2018-20363?
The severity of CVE-2018-20363 is medium, with a severity value of 6.5.
How does CVE-2018-20363 affect LibRaw?
CVE-2018-20363 affects LibRaw 0.19.1 and prior versions.
How can I fix CVE-2018-20363?
To fix CVE-2018-20363, you should update to LibRaw version 0.19.2 or later.
Where can I find more information about CVE-2018-20363?
You can find more information about CVE-2018-20363 at the following references: [http://www.securityfocus.com/bid/106299](http://www.securityfocus.com/bid/106299), [https://github.com/LibRaw/LibRaw/issues/193](https://github.com/LibRaw/LibRaw/issues/193), [https://usn.ubuntu.com/3989-1/](https://usn.ubuntu.com/3989-1/).