Search CVE reports


Toggle filters

11 – 20 of 59 results


CVE-2020-35531

Medium priority

Some fixes available 4 of 60

In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
libraw Not affected Not affected Fixed Fixed
xbmc Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-35530

Medium priority

Some fixes available 4 of 60

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

9 affected packages

darktable, dcraw, digikam, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Fixed Fixed
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Not affected Not affected Fixed Fixed
ufraw Not in release Not in release Not in release Needs evaluation
xbmc Not in release Not in release Not in release Not in release
Show all 9 packages Show less packages

CVE-2020-24890

Medium priority
Not affected

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software...

8 affected packages

darktable, dcraw, exactimage, kodi, libraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Not affected Not affected
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
libraw Not affected Not affected
rawtherapee Not affected Not affected
ufraw Not in release Not affected
xbmc Not in release Not in release
Show all 8 packages Show less packages

CVE-2020-24889

Medium priority
Not affected

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

8 affected packages

libraw, ufraw, darktable, xbmc, dcraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected
ufraw Not in release Not affected
darktable Not affected Not affected
xbmc Not in release Not in release
dcraw Not affected Not affected
exactimage Not affected Not affected
kodi Not affected Not affected
rawtherapee Not affected Not affected
Show all 8 packages Show less packages

CVE-2020-24870

Medium priority
Needs evaluation

Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.

8 affected packages

libraw, ufraw, xbmc, darktable, exactimage...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Needs evaluation
xbmc Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2020-22628

Medium priority

Some fixes available 2 of 53

Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.

9 affected packages

xbmc, libraw, ufraw, darktable, exactimage...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Fixed Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Not affected Not affected Fixed Not affected
Show all 9 packages Show less packages

CVE-2020-15503

Low priority

Some fixes available 2 of 79

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs...

8 affected packages

kodi, libraw, rawtherapee, dcraw, exactimage...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Not affected Not affected Fixed Fixed
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
xbmc Not in release Not in release Not in release Not in release
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2020-15365

Medium priority
Needs evaluation

LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.

8 affected packages

xbmc, kodi, darktable, libraw, ufraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xbmc Not in release Not in release Not in release Not in release
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2018-5819

Low priority

Some fixes available 3 of 87

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

8 affected packages

exactimage, kodi, xbmc, libraw, ufraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xbmc Not in release Not in release Not in release Not in release
libraw Not affected Not affected Not affected Fixed
ufraw Not in release Not in release Not in release Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2018-5818

Low priority

Some fixes available 3 of 87

An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to trigger an infinite loop.

8 affected packages

darktable, libraw, dcraw, exactimage, ufraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Not affected Not affected Not affected Fixed
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release Needs evaluation
xbmc Not in release Not in release Not in release Not in release
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages