CVE-2020-15503
published 2020-07-02CVE-2020-15503: LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.67%
88.3th percentile
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libraw | < libraw 0.20.0-4 (bookworm) | libraw 0.20.0-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libraw | libraw | <= 0.19.5 | — |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| msrc | azl3_libraw_0.19.5-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2w4r-7g95-jpmw: LibRaw before 0
ghsa_unreviewed·2022-05-24
CVE-2020-15503 [MEDIUM] CWE-20 GHSA-2w4r-7g95-jpmw: LibRaw before 0
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
OSV
CVE-2020-15503: LibRaw before 0
osv·2020-07-02·CVSS 7.5
CVE-2020-15503 [HIGH] CVE-2020-15503: LibRaw before 0
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2022-11-07
CVE-2020-15503 LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: Several security issues were fixed in LibRaw.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, a remote attacker could cause applications linked against LibRaw to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Microsoft
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp postprocessing/mem_image.cpp and utils/thumb_utils.cpp. For example malloc(sizeof(libraw_processed_ima
vendor_msrc·2020-07-14·CVSS 7.5
CVE-2020-15503 [HIGH] CWE-20 LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp postprocessing/mem_image.cpp and utils/thumb_utils.cpp. For example malloc(sizeof(libraw_processed_ima
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp postprocessing/mem_image.cpp and utils/thumb_utils.cpp. For example malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to
Red Hat
LibRaw: lack of thumbnail size range check can lead to buffer overflow
vendor_redhat·2020-06-22·CVSS 7.5
CVE-2020-15503 [HIGH] CWE-120 LibRaw: lack of thumbnail size range check can lead to buffer overflow
LibRaw: lack of thumbnail size range check can lead to buffer overflow
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
Statement: While the vulnerable code exists in versions of LibRaw shipped with Red Hat Enterprise Linux 7 and 8, LibRaw is not used in services which accept data directly from a network, reducing impact.
Package: dcraw (Red Hat Enterprise Linux 6) - Not affected
Package: dcraw (Red Hat Enterprise Linux 7) - Not affected
Package: libkdcraw (Red Hat Enterprise Linux 7) - Not affected
Package: LibRaw (Red Hat Enterprise Linux 7) - Fix deferred
Package: dcraw (Red
Debian
CVE-2020-15503: libraw - LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders...
vendor_debian·2020·CVSS 7.5
CVE-2020-15503 [HIGH] CVE-2020-15503: libraw - LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders...
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15503 mingw-LibRaw: LibRaw: lack of thumbnail size range check can lead to buffer overflow [fedora-all]
bugzilla·2020-07-02·CVSS 7.5
CVE-2020-15503 [HIGH] CVE-2020-15503 mingw-LibRaw: LibRaw: lack of thumbnail size range check can lead to buffer overflow [fedora-all]
CVE-2020-15503 mingw-LibRaw: LibRaw: lack of thumbnail size range check can lead to buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2020-15503 LibRaw: lack of thumbnail size range check can lead to buffer overflow [fedora-all]
bugzilla·2020-07-02·CVSS 7.5
CVE-2020-15503 [HIGH] CVE-2020-15503 LibRaw: lack of thumbnail size range check can lead to buffer overflow [fedora-all]
CVE-2020-15503 LibRaw: lack of thumbnail size range check can lead to buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2020-15503 LibRaw: lack of thumbnail size range check can lead to buffer overflow
bugzilla·2020-07-02·CVSS 7.5
CVE-2020-15503 [HIGH] CVE-2020-15503 LibRaw: lack of thumbnail size range check can lead to buffer overflow
CVE-2020-15503 LibRaw: lack of thumbnail size range check can lead to buffer overflow
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
Reference and upstream commit:
https://github.com/LibRaw/LibRaw/commit/20ad21c0d87ca80217aee47533d91e633ce1864d
Discussion:
Created LibRaw tracking bugs for this issue:
Affects: fedora-all [bug 1853478]
Created mingw-LibRaw tracking bugs for this issue:
Affects: fedora-all [bug 1853479]
---
This flaw exists in libraw_cxx.cpp instead of the files listed in the upstream patch. The vulnerable methods LibRaw::dcraw_make_mem_thumb() and LibRaw::kod
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00075.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00001.htmlhttps://github.com/LibRaw/LibRaw/commit/20ad21c0d87ca80217aee47533d91e633ce1864dhttps://github.com/LibRaw/LibRaw/compare/0.20-Beta3...0.20-RC1https://lists.debian.org/debian-lts-announce/2022/11/msg00042.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HM2DS6HA4YZREI3BYGS75M6D76WMW62/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSXAJKZ4VNDYVQULJNY4XDPWHIJDTB4P/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNGDWTO45TU4KGND75EUUEGUMNSOYC7H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCVKD7PTO7UQAVUTBHJAKBKYLPQQGAMZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y34ALB34P3NGQXLF7BG7R6DGRX6XL2JN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZETDVPZQWZWVGIG6JTIEKP5KPVMUE7Y/https://www.libraw.org/news/libraw-0-20-rc1http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00075.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00001.htmlhttps://github.com/LibRaw/LibRaw/commit/20ad21c0d87ca80217aee47533d91e633ce1864dhttps://github.com/LibRaw/LibRaw/compare/0.20-Beta3...0.20-RC1https://lists.debian.org/debian-lts-announce/2022/11/msg00042.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HM2DS6HA4YZREI3BYGS75M6D76WMW62/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSXAJKZ4VNDYVQULJNY4XDPWHIJDTB4P/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DNGDWTO45TU4KGND75EUUEGUMNSOYC7H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCVKD7PTO7UQAVUTBHJAKBKYLPQQGAMZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y34ALB34P3NGQXLF7BG7R6DGRX6XL2JN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZETDVPZQWZWVGIG6JTIEKP5KPVMUE7Y/https://www.libraw.org/news/libraw-0-20-rc1
2020-07-02
Published