Bug 2122360 (CVE-2020-35534)
| Summary: | CVE-2020-35534 LibRaw: Memory corruption in "crxFreeSubbandData()" function | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
| Component: | vulnerability | Assignee: | Nobody <nobody> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | core-kernel-mgr, dchen, debarshir, epel-packagers-sig, gwync, hobbes1069, jshortt, manisandro, mattdm, mattia.verga, michel, ngompa13, sebastian, siddharth.kde, sipoyare, than, thibault |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | LibRaw 0.21-Beta1, LibRaw 0.20.2, LibRaw 0.20.1, LibRaw 0.20.0, LibRaw 0.20-RC2 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A vulnerability was found in LibRaw. There is memory corruption within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2135637 | ||
| Bug Blocks: | 2122363 | ||
|
Description
Pedro Sampaio
2022-08-29 21:05:22 UTC
What's the severity of this CVE? Low? For what it's worth, this CVE neither affects the LibRaw package in Fedora (F >= 35 has 0.20.2) nor in RHEL 9 (has 0.20.2). I didn't check packages that carry other copies of the same code (eg., dcraw). |