In LibRaw, an out-of-bounds read vulnerability exists within the simple_decode_row() function (librawsrcx3fx3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libraw | Libraw | 0.20.0 (including) | 0.20.0 (including) |
Libraw | Libraw | 0.20.0-rc2 (including) | 0.20.0-rc2 (including) |
Libraw | Libraw | 0.20.1 (including) | 0.20.1 (including) |
Libraw | Libraw | 0.20.2 (including) | 0.20.2 (including) |
Libraw | Libraw | 0.21.0-beta1 (including) | 0.21.0-beta1 (including) |
Darktable | Ubuntu | bionic | * |
Darktable | Ubuntu | kinetic | * |
Darktable | Ubuntu | lunar | * |
Darktable | Ubuntu | mantic | * |
Darktable | Ubuntu | trusty | * |
Darktable | Ubuntu | xenial | * |
Dcraw | Ubuntu | bionic | * |
Dcraw | Ubuntu | kinetic | * |
Dcraw | Ubuntu | lunar | * |
Dcraw | Ubuntu | mantic | * |
Dcraw | Ubuntu | trusty | * |
Dcraw | Ubuntu | xenial | * |
Digikam | Ubuntu | bionic | * |
Digikam | Ubuntu | kinetic | * |
Digikam | Ubuntu | lunar | * |
Digikam | Ubuntu | mantic | * |
Digikam | Ubuntu | trusty | * |
Digikam | Ubuntu | xenial | * |
Exactimage | Ubuntu | bionic | * |
Exactimage | Ubuntu | kinetic | * |
Exactimage | Ubuntu | lunar | * |
Exactimage | Ubuntu | mantic | * |
Exactimage | Ubuntu | trusty | * |
Exactimage | Ubuntu | xenial | * |
Kodi | Ubuntu | bionic | * |
Kodi | Ubuntu | kinetic | * |
Kodi | Ubuntu | lunar | * |
Kodi | Ubuntu | mantic | * |
Kodi | Ubuntu | xenial | * |
Libraw | Ubuntu | bionic | * |
Libraw | Ubuntu | focal | * |
Libraw | Ubuntu | trusty | * |
Libraw | Ubuntu | upstream | * |
Libraw | Ubuntu | xenial | * |
Rawtherapee | Ubuntu | bionic | * |
Rawtherapee | Ubuntu | kinetic | * |
Rawtherapee | Ubuntu | lunar | * |
Rawtherapee | Ubuntu | mantic | * |
Rawtherapee | Ubuntu | trusty | * |
Rawtherapee | Ubuntu | xenial | * |
Ufraw | Ubuntu | bionic | * |
Ufraw | Ubuntu | trusty | * |
Ufraw | Ubuntu | xenial | * |
Xbmc | Ubuntu | trusty | * |