CVE-2020-24890: Null Pointer Dereference
DISPUTED libraw 20.0 has a null pointer dereference vulnerability in parsetiffifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24890?
CVE-2020-24890 is a null pointer dereference vulnerability in libraw 20.0.
How severe is CVE-2020-24890?
CVE-2020-24890 has a severity rating of medium with a CVSS score of 5.5.
How does CVE-2020-24890 occur?
CVE-2020-24890 occurs when the software is compiled in a certain way.
How can I fix CVE-2020-24890?
To fix CVE-2020-24890, update to a version of libraw that is not affected.
Where can I find more information about CVE-2020-24890?
More information about CVE-2020-24890 can be found at the following references: [Link 1](https://github.com/LibRaw/LibRaw/issues/335), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWHUZCRMGOC3QS6C65KWBM6ZJM25V6HI/), [Link 3](https://security.gentoo.org/glsa/202010-05)