Lucene search

K
rosalinuxROSA LABROSA-SA-2024-2474
HistorySep 03, 2024 - 12:11 p.m.

Advisory ROSA-SA-2024-2474

2024-09-0312:11:57
ROSA LAB
abf.rosalinux.ru
4
libraw
vulnerability
denial of service
rosa-chrome
memory corruption
image processing

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

software: libraw 0.20.2
OS: ROSA-CHROME

package_evr_string: libraw-0.20.2-4

CVE-ID: CVE-2020-22628
BDU-ID: 2023-05897
CVE-Crit: MEDIUM.
CVE-DESC.: A vulnerability in the LibRaw::stretch() function of the LibRaw image processing library is related to an operation exceeding buffer boundaries in memory when processing CRW files. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of service
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update libraw

CVE-ID: CVE-2020-35533
BDU-ID: 2023-01107
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability in the LibRaw::adobe_copy_pixel() function of the LibRaw image processing library is related to an operation exceeding buffer boundaries in memory. Exploitation of the vulnerability could allow an attacker to cause a denial of service using a specially crafted malicious file
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update libraw

CVE-ID: CVE-2020-35532
BDU-ID: 2023-05698
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability in the x3f_utils_patched.cpp component of the LibRaw image processing library is related to reading beyond buffer boundaries in memory. Exploitation of the vulnerability could allow an attacker to cause a denial of service
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update libraw

CVE-ID: CVE-2020-35531
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: LibRaw has a vulnerability of reading beyond allocated memory in get_huffman_diff() (libraw\src\x3f\x3f\x3f_utils_patched.cpp) when reading data from an image file.
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update libraw

CVE-ID: CVE-2020-35534
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: LibRaw has a memory corruption vulnerability in the “crxFreeSubbandData()” function (libraw\src\decoders\crx.cpp) when processing cr3 files.
CVE-STATUS: Fixed
CVE-REV: To close, execute command: sudo dnf update libraw

CVE-ID: CVE-2020-35535
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: LibRaw has a vulnerability of reading outside of allocated memory in the function “LibRaw::parseSonySRF()” (libraw\src\metadata\sony.cpp) when processing srf files.
CVE-STATUS: Fixed
CVE-REV: To close, execute command: sudo dnf update libraw

CVE-ID: CVE-2020-35530
BDU-ID: 2022-06765
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability in the new_node() function (libraw\src\x3f\x3f\x3f_utils_patched.cpp) of the LibRaw image processing library is related to writing beyond buffer boundaries. Exploitation of the vulnerability could allow an attacker to cause a denial of service
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update libraw

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchlibraw< 0.20.2UNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High