libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libraw | Libraw | 0.20.0 (including) | 0.20.0 (including) |
| Darktable | Ubuntu | trusty | * |
| Dcraw | Ubuntu | trusty | * |
| Exactimage | Ubuntu | trusty | * |
| Libraw | Ubuntu | trusty | * |
| Rawtherapee | Ubuntu | trusty | * |
| Ufraw | Ubuntu | trusty | * |
| Xbmc | Ubuntu | trusty | * |