Out-of-Bounds Read Vulnerability in LibRaw Affects Image Processing
CVE-2020-35533
5.5MEDIUM
What is CVE-2020-35533?
An out-of-bounds read vulnerability exists in the LibRaw library, specifically within the 'LibRaw::adobe_copy_pixel()' function found in the 'libraw/src/decoders/dng.cpp' file. This flaw occurs when the library attempts to read data from an image file, potentially allowing attackers to gain unintended access to sensitive information in memory. Developers using LibRaw in their applications should ensure they implement the necessary security updates to mitigate any risks associated with this vulnerability.
Affected Version(s)
LibRaw LibRaw 0.21-Beta1, LibRaw 0.20.2, LibRaw 0.20.1, LibRaw 0.20.0, LibRaw 0.20-RC2
