CVE-2020-24890

Name
CVE-2020-24890
Description
libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/LibRaw/LibRaw/issues/335
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWHUZCRMGOC3QS6C65KWBM6ZJM25V6HI/
GENTOO https://security.gentoo.org/glsa/202010-05
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWHUZCRMGOC3QS6C65KWBM6ZJM25V6HI/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libraw:libraw:0.20.0:*:*:*:*:*:*:* libraw == None == 0.20.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status