Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-35530

Опубликовано: 01 сент. 2022
Источник: debian

Описание

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librawfixed0.20.0-4package

Примечания

  • https://github.com/LibRaw/LibRaw/commit/11c4db253ef2c9bb44247b578f5caa57c66a1eeb (0.20-RC2)

  • https://github.com/LibRaw/LibRaw/issues/272

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVSS3: 5.5
redhat
почти 6 лет назад

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVSS3: 5.5
nvd
больше 3 лет назад

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVSS3: 5.5
github
больше 3 лет назад

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость функции new_node() (libraw\src\x3f\x3f_utils_patched.cpp) библиотеки для обработки изображений LibRaw, позволяющая нарушителю вызвать отказ в обслуживании