Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15503

Опубликовано: 22 июн. 2020
Источник: redhat
CVSS3: 7.5

Описание

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.

Отчет

While the vulnerable code exists in versions of LibRaw shipped with Red Hat Enterprise Linux 7 and 8, LibRaw is not used in services which accept data directly from a network, reducing impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dcrawNot affected
Red Hat Enterprise Linux 7dcrawNot affected
Red Hat Enterprise Linux 7libkdcrawNot affected
Red Hat Enterprise Linux 7LibRawFix deferred
Red Hat Enterprise Linux 8dcrawNot affected
Red Hat Enterprise Linux 8LibRawFixedRHSA-2020:445104.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1853477LibRaw: lack of thumbnail size range check can lead to buffer overflow

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.

CVSS3: 7.5
nvd
около 5 лет назад

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.

CVSS3: 7.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
около 5 лет назад

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affect ...

suse-cvrf
около 5 лет назад

Security update for libraw

7.5 High

CVSS3