First published: Fri Mar 12 2021(Updated: )
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Leptonica | <1.80.0 | |
Fedora | =32 | |
Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36280 is classified as a high severity vulnerability due to the potential for heap-based buffer over-reads.
To fix CVE-2020-36280, upgrade Leptonica to version 1.80.0 or later.
CVE-2020-36280 affects all versions of Leptonica prior to 1.80.0.
Yes, CVE-2020-36280 can potentially be exploited to cause application crashes or unexpected behavior.
CVE-2020-36280 is relevant to Fedora versions 32 and 33 due to their use of Leptonica.