Bug 2122339 (CVE-2020-35530)
| Summary: | CVE-2020-35530 LibRaw: Out of bounds write in new_node() function | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED WONTFIX | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | alekcejk, core-kernel-mgr, dchen, debarshir, epel-packagers-sig, fenlason, gwync, hobbes1069, jshortt, kde-sig, manisandro, mattdm, mattia.verga, michel, ngompa13, nphilipp, rdieter, sebastian, sergio, siddharth.kde, sipoyare, smparrish, tdawson, than, thibault, viktor.vix.jancik |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | LibRaw 0.21-Beta1, LibRaw 0.20.2, LibRaw 0.20.1, LibRaw 0.20.0, LibRaw 0.20-RC2 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A vulnerability was found in LibRaw. An out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) can be triggered via a crafted X3F file.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-11-29 22:30:49 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2122363 | ||
|
Description
Pedro Sampaio
2022-08-29 20:01:11 UTC
What's the severity of this CVE? Moderate? For what it's worth, this CVE neither affects the LibRaw package in Fedora (F >= 35 has 0.20.2) nor in RHEL 9 (has 0.20.2). I didn't check packages that carry other copies of the same code (eg., dcraw). This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-35530 |