Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24890

Опубликовано: 16 сент. 2020
Источник: nvd
CVSS3: 5.5
CVSS2: 2.6
EPSS Низкий

Описание

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libraw:libraw:0.20.0:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.00449
Низкий

5.5 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way

CVSS3: 5.3
redhat
больше 5 лет назад

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way

CVSS3: 5.5
debian
больше 5 лет назад

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff ...

CVSS3: 5.5
github
больше 3 лет назад

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution.

EPSS

Процентиль: 63%
0.00449
Низкий

5.5 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-476