First published: Thu Mar 11 2021(Updated: )
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Leptonica | <1.80.0 | |
Linux kernel | ||
Fedora | =32 | |
Fedora | =33 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36278 has a medium severity level due to its potential to cause a heap-based buffer over-read.
To fix CVE-2020-36278, upgrade Leptonica to version 1.80.0 or later.
Leptonica versions prior to 1.80.0 are affected by CVE-2020-36278.
CVE-2020-36278 may allow for exploitation in certain contexts, but typically requires local access to the system.
CVE-2020-36278 impacts Leptonica installations on various Linux distributions, including specific versions of Fedora and Debian.