First published: Wed Sep 16 2020(Updated: )
** DISPUTED ** libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw Libraw | =0.20.0 | |
=0.20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24890 is a null pointer dereference vulnerability in libraw 20.0.
CVE-2020-24890 has a severity rating of medium with a CVSS score of 5.5.
CVE-2020-24890 occurs when the software is compiled in a certain way.
To fix CVE-2020-24890, update to a version of libraw that is not affected.
More information about CVE-2020-24890 can be found at the following references: [Link 1](https://github.com/LibRaw/LibRaw/issues/335), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWHUZCRMGOC3QS6C65KWBM6ZJM25V6HI/), [Link 3](https://security.gentoo.org/glsa/202010-05)