CVE-2020-22628
published 2023-08-22CVE-2020-22628: Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.68%
48.7th percentile
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libraw | < libraw 0.20.0-4 (bookworm) | libraw 0.20.0-4 (bookworm) |
| libraw | libraw | <= 0.19.5 | — |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
digikam vulnerabilities
osv·2025-02-13·CVSS 5.5
CVE-2017-0691 [MEDIUM] digikam vulnerabilities
digikam vulnerabilities
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive in
OSV
CVE-2020-22628: Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio
osv·2023-08-22·CVSS 6.5
CVE-2020-22628 [MEDIUM] CVE-2020-22628: Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
GHSA
GHSA-c4mp-wp8f-qrg6: Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio
ghsa_unreviewed·2023-08-22
CVE-2020-22628 [MEDIUM] CWE-120 GHSA-c4mp-wp8f-qrg6: Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
Ubuntu
digiKam vulnerabilities
vendor_ubuntu·2025-02-13·CVSS 5.5
CVE-2020-35531 [MEDIUM] digiKam vulnerabilities
Title: digiKam vulnerabilities
Summary: Several security issues were fixed in digiKam.
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file
Ubuntu
LibRaw vulnerability
vendor_ubuntu·2023-09-18
CVE-2020-22628 LibRaw vulnerability
Title: LibRaw vulnerability
Summary: LibRaw could be made to crash if it opened a specially crafted file.
It was discovered that LibRaw incorrectly handled certain photo files. If a
user o automated system were tricked into processing a specially crafted
photo file, a remote attacker could possibly cause applications linked
against LibRaw to crash, resulting in a denial of service.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
libraw: Out of bounds read in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp
vendor_redhat·2023-08-22·CVSS 6.5
CVE-2020-22628 [MEDIUM] CWE-125 libraw: Out of bounds read in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp
libraw: Out of bounds read in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
A flaw was found in the libraw library. This issue occurs due to an out-of-bounds read vulnerability that exists within the "LibRaw::stretch()" function (libraw\src\postprocessing\aspect_ratio.cpp) when parsing a crafted CRW file.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: LibRaw (Red Hat Enterprise Linux 7) - Out of support scope
Package: LibRaw (Red Hat Enterprise Linux
Debian
CVE-2020-22628: libraw - Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postpr...
vendor_debian·2020·CVSS 6.5
CVE-2020-22628 [MEDIUM] CVE-2020-22628: libraw - Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postpr...
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
No detection rules found.
No public exploits indexed.
2023-08-22
Published