CVE-2020-35530: Medium severity libraw vulnerability
Published Sep 1, 2022
·Updated
In LibRaw, there is an out-of-bounds write vulnerability within the "newnode()" function (libraw\src\x3f\x3futilspatched.cpp) that can be triggered via a crafted X3F file.
Affected Software
7 affected componentsFixes available
debian/libraw
0.20.2-1+deb11u10.20.2-2.10.21.3-1
Libraw Libraw=0.20.0
Libraw Libraw=0.20.0-rc2
Libraw Libraw=0.20.1
Libraw Libraw=0.20.2
Libraw Libraw=0.21.0-beta1
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Sep 1, 2022
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionWeakness
Feb 13, 2025
Data Sourced
via Ubuntu·11:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:57 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35530?
CVE-2020-35530 is an out-of-bounds write vulnerability in LibRaw.
2
How can I trigger the vulnerability in LibRaw?
The vulnerability in LibRaw can be triggered by using a crafted X3F file.
3
Which versions of LibRaw are affected by CVE-2020-35530?
Versions 0.20.0, 0.20.0-rc2, 0.20.1, 0.20.2, and 0.21.0-beta1 of LibRaw are affected.
4
What is the severity of CVE-2020-35530?
CVE-2020-35530 has a severity rating of 5.5 (medium).
5
How can I fix the vulnerability in LibRaw?
To fix the vulnerability, you should update LibRaw to a version that is not affected by CVE-2020-35530.