CVE-2020-35532: Medium severity libraw vulnerability
Published Sep 1, 2022
·Updated
In LibRaw, an out-of-bounds read vulnerability exists within the "simpledecoderow()" function (libraw\src\x3f\x3futilspatched.cpp) which can be triggered via an image with a large rowstride field.
Affected Software
7 affected componentsFixes available
debian/libraw
0.20.2-1+deb11u10.20.2-2.10.21.3-1
Libraw Libraw=0.20.0
Libraw Libraw=0.20.0-rc2
Libraw Libraw=0.20.1
Libraw Libraw=0.20.2
Libraw Libraw=0.21.0-beta1
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Sep 1, 2022
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 13, 2025
Data Sourced
via Ubuntu·11:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:57 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35532?
CVE-2020-35532 is an out-of-bounds read vulnerability in LibRaw's simple_decode_row() function.
2
How does CVE-2020-35532 occur?
CVE-2020-35532 occurs when an image with a large row_stride field triggers an out-of-bounds read in the simple_decode_row() function.
3
What is the severity of CVE-2020-35532?
The severity of CVE-2020-35532 is medium with a severity value of 5.5.
4
Which software versions are affected by CVE-2020-35532?
Versions 0.20.0, 0.20.0-rc2, 0.20.1, 0.20.2, and 0.21.0-beta1 of Libraw are affected by CVE-2020-35532.
5
How can I fix CVE-2020-35532?
To fix CVE-2020-35532, users should update to a version of Libraw that includes the fix for the vulnerability.