CVE-2021-32142Out-of-bounds Write in Libraw

Severity
7.8HIGHNVD
OSV5.5
EPSS
0.0%
top 93.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateFeb 13

Description

Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/libraw< libraw 0.20.2-2.1 (bookworm)
Debianlibraw/libraw< 0.20.2-1+deb11u1+3
NVDlibraw/libraw0.20.0

Patches

🔴Vulnerability Details

3
OSV
digikam vulnerabilities2025-02-13
GHSA
GHSA-2vqp-59qv-pmrc: Buffer Overflow vulnerability in LibRaw linux/unix v02023-02-17
OSV
CVE-2021-32142: Buffer Overflow vulnerability in LibRaw linux/unix v02023-02-17

📋Vendor Advisories

5
Ubuntu
digiKam vulnerabilities2025-02-13
Ubuntu
LibRaw vulnerabilities2023-06-05
Red Hat
LibRaw: stack buffer overflow in LibRaw_buffer_datastream::gets() in src/libraw_datastream.cpp2023-02-17
Microsoft
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.2023-02-14
Debian
CVE-2021-32142: libraw - Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to es...2021