Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15365

Опубликовано: 15 июн. 2020
Источник: redhat
CVSS3: 7.5

Описание

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

Отчет

Versions of LibRaw shipped with Red Hat Enterprise Linux 7 and 8 are not affected by this flaw because the vulnerable code was introduced in a newer version of LibRaw. CR3 support was not introduced until 0.20-RC1 and the older exif code does not have the same logic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dcrawNot affected
Red Hat Enterprise Linux 7dcrawNot affected
Red Hat Enterprise Linux 7libkdcrawNot affected
Red Hat Enterprise Linux 7LibRawNot affected
Red Hat Enterprise Linux 8dcrawNot affected
Red Hat Enterprise Linux 8LibRawNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1852093LibRaw: out-of-bounds write in parse_exif function in metadata/exif_gps.cpp

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

CVSS3: 6.5
nvd
больше 5 лет назад

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

CVSS3: 6.5
debian
больше 5 лет назад

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in ...

CVSS3: 6.5
github
больше 3 лет назад

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

7.5 High

CVSS3

Уязвимость CVE-2020-15365