7.5
CVSSv3

CVE-2020-36281

Published: 12/03/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Leptonica prior to 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

leptonica leptonica

debian debian linux 9.0

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #985089 CVE-2020-36277 CVE-2020-36278 CVE-2020-36279 CVE-2020-36280 CVE-2020-36281 Package: src:leptonlib; Maintainer for src:leptonlib is Jeff Breidenbach <jab@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 12 Mar 2021 19:06:01 UTC Severity: grave Tags: security, up ...