CVE-2020-36278: High severity leptonica vulnerability
Published Mar 11, 2021
·Updated
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
Affected Software
5 affected components
Leptonica Leptonica<1.80.0
Linux Linux kernel
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Remediation
Event History
Mar 11, 2021
CVE Published
via MITRE·11:59 PM
Data Sourced
via MITRE·11:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36278?
CVE-2020-36278 has a medium severity level due to its potential to cause a heap-based buffer over-read.
2
How do I fix CVE-2020-36278?
To fix CVE-2020-36278, upgrade Leptonica to version 1.80.0 or later.
3
What versions of Leptonica are affected by CVE-2020-36278?
Leptonica versions prior to 1.80.0 are affected by CVE-2020-36278.
4
Can CVE-2020-36278 be exploited remotely?
CVE-2020-36278 may allow for exploitation in certain contexts, but typically requires local access to the system.
5
Which operating systems are impacted by CVE-2020-36278?
CVE-2020-36278 impacts Leptonica installations on various Linux distributions, including specific versions of Fedora and Debian.