CVE-2018-20364: Null Pointer Dereference
Published Dec 22, 2018
·Updated
Last updated 11 July 2025
Other sources
LibRaw::copybayer in librawcxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
— Launchpad
Affected Software
2 affected componentsFixes available
Libraw Libraw<=0.19.1
debian/libraw
0.20.2-1+deb11u10.20.2-1+deb11u20.20.2-2.1+deb12u10.21.4-20.21.5b-1
Remediation
Patch Available
Event History
Dec 22, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:58 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·07:01 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:02 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-20364?
CVE-2018-20364 is a vulnerability in LibRaw 0.19.1 that causes a NULL pointer dereference.
2
How severe is CVE-2018-20364?
CVE-2018-20364 has a severity rating of 6.5 (medium).
3
Which software versions are affected by CVE-2018-20364?
LibRaw versions up to and including 0.19.1 are affected by CVE-2018-20364.
4
How can I fix CVE-2018-20364?
It is recommended to update LibRaw to version 0.19.2 or later to fix CVE-2018-20364.
5
Where can I find more information about CVE-2018-20364?
More information about CVE-2018-20364 can be found at the following references: [securityfocus.com](http://www.securityfocus.com/bid/106299), [LibRaw GitHub issue](https://github.com/LibRaw/LibRaw/issues/194), [Ubuntu Security Notice](https://usn.ubuntu.com/3989-1/).