Описание
Security update for libraw
This update for libraw fixes the following issues:
- security update
- added patches
fix CVE-2020-15503 [bsc#1173674], lack of thumbnail size range check can lead to buffer overflow
- libraw-CVE-2020-15503.patch
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.2
libraw-devel-0.18.9-lp152.5.3.1
libraw-devel-static-0.18.9-lp152.5.3.1
libraw-tools-0.18.9-lp152.5.3.1
libraw16-0.18.9-lp152.5.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:1128-1
- SUSE Security Ratings
- SUSE Bug 1173674
- SUSE CVE CVE-2020-15503 page
Описание
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
Затронутые продукты
openSUSE Leap 15.2:libraw-devel-0.18.9-lp152.5.3.1
openSUSE Leap 15.2:libraw-devel-static-0.18.9-lp152.5.3.1
openSUSE Leap 15.2:libraw-tools-0.18.9-lp152.5.3.1
openSUSE Leap 15.2:libraw16-0.18.9-lp152.5.3.1
Ссылки
- CVE-2020-15503
- SUSE Bug 1173674