Uninitialized Variable in libvips Library Leading to Potential Data Leakage
CVE-2020-20739
5.3MEDIUM
What is CVE-2020-20739?
The libvips library, specifically the im_vips2dz function in the deprecated im_vips2dz.c file, contains an uninitialized variable vulnerability. This flaw can lead to potential leakage of sensitive information such as remote server paths or stack addresses, posing a security risk to systems utilizing affected versions of the library. To mitigate the risk, users are advised to update to version 8.8.2 or later, where this issue is resolved.
