CVE-2020-24870: Buffer Overflow
A flaw was found in libraw. Stack buffer overflow in LibRaw::identifyprocessdngfields in identify.cpp may lead to local denial of service or local arbitrary code execution from a user crafted file.
References:
https://github.com/LibRaw/LibRaw/commit/4feaed4dea636cee4fee010f615881ccf76a096d https://github.com/LibRaw/LibRaw/issues/330
Other sources
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identifyprocessdngfields in identify.cpp.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-24870.
What is the severity of CVE-2020-24870?
The severity of CVE-2020-24870 is high with a CVSS score of 8.8.
What is the affected software?
The affected software is Libraw before version 0.20.1.
How can the stack buffer overflow be triggered?
The stack buffer overflow can be triggered through the LibRaw::identify_process_dng_fields function in identify.cpp.
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability in version 0.20.1 of Libraw.