Lucene search

K
cvelistRedhatCVELIST:CVE-2020-35534
HistorySep 01, 2022 - 5:54 p.m.

CVE-2020-35534

2022-09-0117:54:28
CWE-400
redhat
www.cve.org
7
libraw
memory corruption
crxfreesubbanddata
cr3 files

EPSS

0.001

Percentile

23.6%

In LibRaw, there is a memory corruption vulnerability within the “crxFreeSubbandData()” function (libraw\src\decoders\crx.cpp) when processing cr3 files.

CNA Affected

[
  {
    "product": "LibRaw",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "LibRaw 0.21-Beta1, LibRaw 0.20.2, LibRaw 0.20.1, LibRaw 0.20.0, LibRaw 0.20-RC2"
      }
    ]
  }
]