First published: Thu Sep 01 2022(Updated: )
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libraw Libraw | =0.20.0 | |
Libraw Libraw | =0.20.0-rc2 | |
Libraw Libraw | =0.20.1 | |
Libraw Libraw | =0.20.2 | |
Libraw Libraw | =0.21.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35534 is a memory corruption vulnerability within the "crxFreeSubbandData()" function in LibRaw.
CVE-2020-35534 affects LibRaw versions 0.20.0, 0.20.0-rc2, 0.20.1, 0.20.2, and 0.21.0-beta1.
The severity of CVE-2020-35534 is medium, with a CVSS score of 5.5.
To fix CVE-2020-35534, update your LibRaw installation to a version that includes the fix provided in the official commit.
You can find more information about CVE-2020-35534 in the official GitHub repository of LibRaw, including the commit and associated issue.