CVE-2020-24870
published 2021-06-02CVE-2020-24870: Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.63%
73.5th percentile
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libraw | < libraw 0.20.2-1 (bookworm) | libraw 0.20.2-1 (bookworm) |
| libraw | libraw | < 0.20.1 | 0.20.1 |
| libraw | libraw | >= 0 < 0.20.2-1 | 0.20.2-1 |
| libraw | libraw | >= 0 < 0.20.2-1 | 0.20.2-1 |
| libraw | libraw | >= 0 < 0.20.2-1 | 0.20.2-1 |
| libraw | libraw | >= 0 < 0.20.2-1 | 0.20.2-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p736-65cp-9pj8: Libraw before 0
ghsa_unreviewed·2022-05-24
CVE-2020-24870 [HIGH] CWE-787 GHSA-p736-65cp-9pj8: Libraw before 0
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
OSV
CVE-2020-24870: Libraw before 0
osv·2021-06-02·CVSS 8.8
CVE-2020-24870 [HIGH] CVE-2020-24870: Libraw before 0
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
Red Hat
LibRaw: Stack buffer overflow in LibRaw::identify_process_dng_fields() in identify.cpp
vendor_redhat·2020-08-19·CVSS 8.8
CVE-2020-24870 [HIGH] CWE-120 LibRaw: Stack buffer overflow in LibRaw::identify_process_dng_fields() in identify.cpp
LibRaw: Stack buffer overflow in LibRaw::identify_process_dng_fields() in identify.cpp
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
A stack buffer overflow vulnerability was found in LibRaw. This flaw allows a malicious user to send a crafted image that, when parsed by an application linked to LibRaw, leads to a denial of service or potential code execution.
Statement: LibRaw is not supposed to be used in RHEL by network-facing applications, thus reducing the impact of this flaw.
Package: dcraw (Red Hat Enterprise Linux 6) - Out of support scope
Package: dcraw (Red Hat Enterprise Linux 7) - Out of support scope
Package: libkdcraw (Red Hat Enterprise Linux 7) - Out of support scope
Package: LibRaw (Red Hat Enterprise Linux
Debian
CVE-2020-24870: libraw - Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dn...
vendor_debian·2020·CVSS 8.8
CVE-2020-24870 [HIGH] CVE-2020-24870: libraw - Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dn...
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
Scope: local
bookworm: resolved (fixed in 0.20.2-1)
bullseye: resolved (fixed in 0.20.2-1)
forky: resolved (fixed in 0.20.2-1)
sid: resolved (fixed in 0.20.2-1)
trixie: resolved (fixed in 0.20.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LibRaw/LibRaw/commit/4feaed4dea636cee4fee010f615881ccf76a096dhttps://github.com/LibRaw/LibRaw/issues/330https://security.gentoo.org/glsa/202208-07https://github.com/LibRaw/LibRaw/commit/4feaed4dea636cee4fee010f615881ccf76a096dhttps://github.com/LibRaw/LibRaw/issues/330https://security.gentoo.org/glsa/202208-07
2021-06-02
Published