First published: Thu Sep 01 2022(Updated: )
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw Libraw | =0.20.0 | |
Libraw Libraw | =0.20.0-rc2 | |
Libraw Libraw | =0.20.1 | |
Libraw Libraw | =0.20.2 | |
Libraw Libraw | =0.21.0-beta1 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35532 is an out-of-bounds read vulnerability in LibRaw's simple_decode_row() function.
CVE-2020-35532 occurs when an image with a large row_stride field triggers an out-of-bounds read in the simple_decode_row() function.
The severity of CVE-2020-35532 is medium with a severity value of 5.5.
Versions 0.20.0, 0.20.0-rc2, 0.20.1, 0.20.2, and 0.21.0-beta1 of Libraw are affected by CVE-2020-35532.
To fix CVE-2020-35532, users should update to a version of Libraw that includes the fix for the vulnerability.