Lucene search

K
cvelistRedhatCVELIST:CVE-2020-35535
HistorySep 01, 2022 - 5:54 p.m.

CVE-2020-35535

2022-09-0117:54:23
CWE-125
redhat
www.cve.org
4
libraw
out-of-bounds read
vulnerability
parsesonysrf
srf files

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

23.8%

In LibRaw, there is an out-of-bounds read vulnerability within the “LibRaw::parseSonySRF()” function (libraw\src\metadata\sony.cpp) when processing srf files.

CNA Affected

[
  {
    "product": "LibRaw",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "LibRaw 0.21-Beta1, LibRaw 0.20.2, LibRaw 0.20.1, LibRaw 0.20.0, LibRaw 0.20-RC2"
      }
    ]
  }
]

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

23.8%