NA

CVE-2021-32142

Published: 17/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows malicious user to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libraw libraw 0.20.0

Vendor Advisories

Debian Bug report logs - #1031790 libraw: CVE-2021-32142 Package: src:libraw; Maintainer for src:libraw is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 22 Feb 2023 19:57:01 UTC Severity: important Tags: security, upstrea ...
Synopsis Moderate: LibRaw security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for LibRaw is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a secu ...
Synopsis Moderate: LibRaw security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for LibRaw is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a secu ...
Several vulnerabilities were discovered in libraw, a library for reading RAW files obtained from digital photo cameras, which may result in denial of service or the execution of arbitrary code if specially crafted files are processed For the stable distribution (bullseye), these problems have been fixed in version 0202-1+deb11u1 We recommend th ...
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratiocpp (CVE-2020-22628) In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patchedcpp) that can be triggered via a crafted X3F file (CVE-2020-35530) In LibRaw, an out-of-bounds read v ...
Description<!---->A flaw was found in the LibRaw package A stack buffer overflow in the LibRaw_buffer_datastream::gets() function in src/libraw_datastreamcpp caused by a maliciously crafted file may result in compromised confidentiality and integrity and an application crashA flaw was found in the LibRaw package A stack buffer overflow in the L ...