CVE-2020-35534: Medium severity libraw vulnerability
Published Sep 1, 2022
·Updated
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
Affected Software
5 affected components
Libraw Libraw=0.20.0
Libraw Libraw=0.20.0-rc2
Libraw Libraw=0.20.1
Libraw Libraw=0.20.2
Libraw Libraw=0.21.0-beta1
Remediation
Patch Available
Event History
Sep 1, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-35534?
CVE-2020-35534 is a memory corruption vulnerability within the "crxFreeSubbandData()" function in LibRaw.
2
How does CVE-2020-35534 affect LibRaw?
CVE-2020-35534 affects LibRaw versions 0.20.0, 0.20.0-rc2, 0.20.1, 0.20.2, and 0.21.0-beta1.
3
What is the severity of CVE-2020-35534?
The severity of CVE-2020-35534 is medium, with a CVSS score of 5.5.
4
How can I fix CVE-2020-35534?
To fix CVE-2020-35534, update your LibRaw installation to a version that includes the fix provided in the official commit.
5
Where can I find more information about CVE-2020-35534?
You can find more information about CVE-2020-35534 in the official GitHub repository of LibRaw, including the commit and associated issue.