Memory Corruption Vulnerability in LibRaw's CR3 File Processing
CVE-2020-35534
5.5MEDIUM
What is CVE-2020-35534?
A memory corruption vulnerability exists in the LibRaw library, specifically within the 'crxFreeSubbandData()' function when handling CR3 files. This security flaw can potentially allow attackers to exploit memory misuse, leading to unexpected behavior or system crashes. Proper handling or validation of memory resources is crucial for mitigation. Users are advised to update to the latest version which includes patches addressing this issue.
Affected Version(s)
LibRaw LibRaw 0.21-Beta1, LibRaw 0.20.2, LibRaw 0.20.1, LibRaw 0.20.0, LibRaw 0.20-RC2
