CVE-2020-35533: Medium severity libraw vulnerability
Published Sep 1, 2022
·Updated
In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobecopypixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.
Affected Software
7 affected componentsFixes available
debian/libraw
0.20.2-1+deb11u10.20.2-2.10.21.3-1
Libraw Libraw=0.20.0
Libraw Libraw=0.20.0-rc2
Libraw Libraw=0.20.1
Libraw Libraw=0.20.2
Libraw Libraw=0.21.0-beta1
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Sep 1, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Feb 17, 2025
Data Sourced
via Ubuntu·11:58 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:58 PM
Description
Data Sourced
via Debian·11:59 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2020-35533?
CVE-2020-35533 is an out-of-bounds read vulnerability in the LibRaw library.
2
How severe is CVE-2020-35533?
CVE-2020-35533 has a severity rating of 5.5 (medium).
3
Which software versions are affected by CVE-2020-35533?
CVE-2020-35533 affects versions 0.20.0, 0.20.0-rc2, 0.20.1, 0.20.2, and 0.21.0-beta1 of the LibRaw library.
4
How can I fix CVE-2020-35533?
To fix CVE-2020-35533, users should update to a patched version of the LibRaw library.
5
Where can I find more information about CVE-2020-35533?
You can find more information about CVE-2020-35533 on the official LibRaw GitHub repository and the Debian LTS announcement.