CVE-2021-32142
published 2023-02-17CVE-2021-32142: Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.42%
34.3th percentile
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libraw | < libraw 0.20.2-2.1 (bookworm) | libraw 0.20.2-2.1 (bookworm) |
| libraw | libraw | — | — |
| libraw | libraw | >= 0 < 0.20.2-1+deb11u1 | 0.20.2-1+deb11u1 |
| libraw | libraw | >= 0 < 0.20.2-2.1 | 0.20.2-2.1 |
| libraw | libraw | >= 0 < 0.20.2-2.1 | 0.20.2-2.1 |
| libraw | libraw | >= 0 < 0.20.2-2.1 | 0.20.2-2.1 |
| msrc | azl3_libraw_0.21.3-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
digiKam vulnerabilities
vendor_ubuntu·2025-02-13·CVSS 5.5
CVE-2020-35531 [MEDIUM] digiKam vulnerabilities
Title: digiKam vulnerabilities
Summary: Several security issues were fixed in digiKam.
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file
Ubuntu
LibRaw vulnerabilities
vendor_ubuntu·2023-06-05
CVE-2023-1729 LibRaw vulnerabilities
Title: LibRaw vulnerabilities
Summary: Several security issues were fixed in LibRaw.
It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, a remote attacker could cause applications linked against LibRaw to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
LibRaw: stack buffer overflow in LibRaw_buffer_datastream::gets() in src/libraw_datastream.cpp
vendor_redhat·2023-02-17·CVSS 7.8
CVE-2021-32142 [HIGH] CWE-121 LibRaw: stack buffer overflow in LibRaw_buffer_datastream::gets() in src/libraw_datastream.cpp
LibRaw: stack buffer overflow in LibRaw_buffer_datastream::gets() in src/libraw_datastream.cpp
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
A flaw was found in the LibRaw package. A stack buffer overflow in the LibRaw_buffer_datastream::gets() function in src/libraw_datastream.cpp caused by a maliciously crafted file may result in compromised confidentiality and integrity and an application crash.
Microsoft
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
vendor_msrc·2023-02-14·CVSS 7.8
CVE-2021-32142 [HIGH] CWE-787 Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to re
Debian
CVE-2021-32142: libraw - Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to es...
vendor_debian·2021·CVSS 7.8
CVE-2021-32142 [HIGH] CVE-2021-32142: libraw - Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to es...
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
Scope: local
bookworm: resolved (fixed in 0.20.2-2.1)
bullseye: resolved (fixed in 0.20.2-1+deb11u1)
forky: resolved (fixed in 0.20.2-2.1)
sid: resolved (fixed in 0.20.2-2.1)
trixie: resolved (fixed in 0.20.2-2.1)
OSV
digikam vulnerabilities
osv·2025-02-13·CVSS 5.5
CVE-2017-0691 [MEDIUM] digikam vulnerabilities
digikam vulnerabilities
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive in
GHSA
GHSA-2vqp-59qv-pmrc: Buffer Overflow vulnerability in LibRaw linux/unix v0
ghsa_unreviewed·2023-02-17
CVE-2021-32142 [CRITICAL] CWE-787 GHSA-2vqp-59qv-pmrc: Buffer Overflow vulnerability in LibRaw linux/unix v0
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
OSV
CVE-2021-32142: Buffer Overflow vulnerability in LibRaw linux/unix v0
osv·2023-02-17·CVSS 7.8
CVE-2021-32142 [HIGH] CVE-2021-32142: Buffer Overflow vulnerability in LibRaw linux/unix v0
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LibRaw/LibRaw/commit/bc3aaf4223fdb70d52d470dae65c5a7923ea2a49https://github.com/LibRaw/LibRaw/issues/400https://github.com/gtt1995https://lists.debian.org/debian-lts-announce/2023/05/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E7TEZ7CLRNYYQZJ5NJGZXK6YJU46WH2L/https://www.debian.org/security/2023/dsa-5412https://www.libraw.org/https://github.com/LibRaw/LibRaw/commit/bc3aaf4223fdb70d52d470dae65c5a7923ea2a49https://github.com/LibRaw/LibRaw/issues/400https://github.com/gtt1995https://lists.debian.org/debian-lts-announce/2023/05/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E7TEZ7CLRNYYQZJ5NJGZXK6YJU46WH2L/https://www.debian.org/security/2023/dsa-5412https://www.libraw.org/
2023-02-17
Published