First published: Fri Nov 20 2020(Updated: )
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/vips | 8.7.4-1+deb10u1 8.10.5-2 8.14.1-3+deb12u1 8.15.1-1 8.15.2-1 | |
ubuntu/vips | <8.4.5-1ubuntu0.1~ | 8.4.5-1ubuntu0.1~ |
ubuntu/vips | <8.9.0-1 | 8.9.0-1 |
ubuntu/vips | <8.2.2-1ubuntu0.1~ | 8.2.2-1ubuntu0.1~ |
LibVIRT | <8.8.2 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20739 is a vulnerability in the libvips library before version 8.8.2 that may cause the leakage of remote server path or stack address.
CVE-2020-20739 has a severity level of 5.3, which is considered medium.
CVE-2020-20739 affects libvips versions up to, but not including, 8.8.2.
To fix CVE-2020-20739, update libvips to version 8.8.2 or later.
You can find more information about CVE-2020-20739 at the following references: [link1], [link2], [link3].