CVE-2018-20365: Buffer Overflow
Last updated 11 July 2025
Other sources
LibRaw::raw2image() in librawcxx.cpp has a heap-based buffer overflow.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20365?
CVE-2018-20365 is a vulnerability in LibRaw::raw2image() in libraw_cxx.cpp that allows for a heap-based buffer overflow.
How severe is CVE-2018-20365?
CVE-2018-20365 has a severity of 6.5 (Medium).
Which software is affected by CVE-2018-20365?
Libraw version 0.19.2-2, 0.19.2-2+deb10u4, 0.20.2-1+deb11u1, 0.20.2-2.1, and 0.21.1-7 are affected on Debian. libraw version 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1, 0.19.2-2, and 0.17.1-1ubuntu0.5 are affected on Ubuntu. The vulnerability affects Libraw version up to and including 0.19.1 on all platforms.
How do I fix CVE-2018-20365 on Debian?
Apply the following remedies on Debian: libraw version 0.19.2-2 or later.
How do I fix CVE-2018-20365 on Ubuntu?
Apply the following remedies on Ubuntu: libraw version 0.18.8-1ubuntu0.3, 0.18.13-1ubuntu0.1, 0.19.2-2, or 0.17.1-1ubuntu0.5.