CVE-2020-20739: Medium severity libvirt vulnerability
Published Nov 20, 2020
·Updated
imvips2dz in /libvips/libvips/deprecated/imvips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
Affected Software
7 affected componentsFixes available
debian/vips
8.7.4-1+deb10u18.10.5-28.14.1-3+deb12u18.15.1-18.15.2-1
ubuntu/vips<8.4.5-1ubuntu0.1~
8.4.5-1ubuntu0.1~
ubuntu/vips<8.9.0-1
8.9.0-1
ubuntu/vips<8.2.2-1ubuntu0.1~
8.2.2-1ubuntu0.1~
libvips libvips<8.8.2
Debian Debian Linux=9.0
Fedoraproject Fedora=32
Remediation
Event History
Nov 20, 2020
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:44 PM
Description
Frequently Asked Questions
1
What is CVE-2020-20739?
CVE-2020-20739 is a vulnerability in the libvips library before version 8.8.2 that may cause the leakage of remote server path or stack address.
2
What is the severity of CVE-2020-20739?
CVE-2020-20739 has a severity level of 5.3, which is considered medium.
3
Which software versions are affected by CVE-2020-20739?
CVE-2020-20739 affects libvips versions up to, but not including, 8.8.2.
4
How do I fix CVE-2020-20739?
To fix CVE-2020-20739, update libvips to version 8.8.2 or later.
5
Where can I find more information about CVE-2020-20739?
You can find more information about CVE-2020-20739 at the following references: [link1], [link2], [link3].