CVE-2020-35532
published 2022-09-01CVE-2020-35532: In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered…
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.37%
29.5th percentile
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libraw | < libraw 0.20.0-4 (bookworm) | libraw 0.20.0-4 (bookworm) |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
| libraw | libraw | >= 0 < 0.20.0-4 | 0.20.0-4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
digiKam vulnerabilities
vendor_ubuntu·2025-02-13·CVSS 5.5
CVE-2020-35531 [MEDIUM] digiKam vulnerabilities
Title: digiKam vulnerabilities
Summary: Several security issues were fixed in digiKam.
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2022-11-07
CVE-2020-15503 LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: Several security issues were fixed in LibRaw.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, a remote attacker could cause applications linked against LibRaw to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
LibRaw: Out-of-bounds read in simple_decode_row() function
vendor_redhat·2020-04-02·CVSS 5.5
CVE-2020-35532 [MEDIUM] CWE-125 LibRaw: Out-of-bounds read in simple_decode_row() function
LibRaw: Out-of-bounds read in simple_decode_row() function
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
A vulnerability was found in LibRaw. An out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp), which can be triggered via an image with a large row_stride field.
Package: libraw1394 (Red Hat Enterprise Linux 6) - Out of support scope
Package: LibRaw (Red Hat Enterprise Linux 7) - Out of support scope
Package: libraw1394 (Red Hat Enterprise Linux 7) - Out of support scope
Package: LibRaw (Red Hat Enterprise Linux 8) - Not affected
Package: libraw1394 (Red Hat En
Debian
CVE-2020-35532: libraw - In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_...
vendor_debian·2020·CVSS 5.5
CVE-2020-35532 [MEDIUM] CVE-2020-35532: libraw - In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_...
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
Scope: local
bookworm: resolved (fixed in 0.20.0-4)
bullseye: resolved (fixed in 0.20.0-4)
forky: resolved (fixed in 0.20.0-4)
sid: resolved (fixed in 0.20.0-4)
trixie: resolved (fixed in 0.20.0-4)
OSV
digikam vulnerabilities
osv·2025-02-13·CVSS 5.5
CVE-2017-0691 [MEDIUM] digikam vulnerabilities
digikam vulnerabilities
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive in
GHSA
GHSA-fc2r-q5xw-m9fm: In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched
ghsa_unreviewed·2022-09-02
CVE-2020-35532 [MEDIUM] CWE-125 GHSA-fc2r-q5xw-m9fm: In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
OSV
CVE-2020-35532: In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched
osv·2022-09-01·CVSS 5.5
CVE-2020-35532 [MEDIUM] CVE-2020-35532: In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LibRaw/LibRaw/commit/5ab45b085898e379fedc6b113e2e82a890602b1ehttps://github.com/LibRaw/LibRaw/issues/271https://lists.debian.org/debian-lts-announce/2022/09/msg00024.htmlhttps://github.com/LibRaw/LibRaw/commit/5ab45b085898e379fedc6b113e2e82a890602b1ehttps://github.com/LibRaw/LibRaw/issues/271https://lists.debian.org/debian-lts-announce/2022/09/msg00024.html
2022-09-01
Published