Bugzilla – Bug 1215308
VUL-0: CVE-2020-22628: libraw: stretch() function in libraw\src\postprocessing\aspect_ratio.cpp
Last modified: 2023-10-09 07:28:36 UTC
CVE-2020-22628 Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp. References: https://github.com/LibRaw/LibRaw/issues/269 https://github.com/LibRaw/LibRaw/commit/84bbb972d94a965f70302b85738778443540774a References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22628 https://bugzilla.redhat.com/show_bug.cgi?id=2234992 https://www.cve.org/CVERecord?id=CVE-2020-22628 https://github.com/LibRaw/LibRaw/issues/269 https://lists.debian.org/debian-lts-announce/2023/09/msg00007.html
Submitted for TW,15sp4,15,12/libraw. I believe all fixed.
This is an autogenerated message for OBS integration: This bug (1215308) was mentioned in https://build.opensuse.org/request/show/1111919 Factory / libraw
SUSE-SU-2023:3968-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1215308 CVE References: CVE-2020-22628 Sources used: openSUSE Leap 15.4 (src): libraw-0.20.2-150400.3.9.1 openSUSE Leap 15.5 (src): libraw-0.20.2-150400.3.9.1 Desktop Applications Module 15-SP4 (src): libraw-0.20.2-150400.3.9.1 Desktop Applications Module 15-SP5 (src): libraw-0.20.2-150400.3.9.1 SUSE Package Hub 15 15-SP5 (src): libraw-0.20.2-150400.3.9.1 SUSE Linux Enterprise Workstation Extension 15 SP4 (src): libraw-0.20.2-150400.3.9.1 SUSE Linux Enterprise Workstation Extension 15 SP5 (src): libraw-0.20.2-150400.3.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:3967-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1215308 CVE References: CVE-2020-22628 Sources used: SUSE Linux Enterprise Workstation Extension 12 12-SP5 (src): libraw-0.15.4-42.1 SUSE Linux Enterprise Software Development Kit 12 SP5 (src): libraw-0.15.4-42.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:3966-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1215308 CVE References: CVE-2020-22628 Sources used: openSUSE Leap 15.4 (src): libraw-0.18.9-150000.3.23.1 SUSE Linux Enterprise Workstation Extension 15 SP4 (src): libraw-0.18.9-150000.3.23.1 SUSE Linux Enterprise Workstation Extension 15 SP5 (src): libraw-0.18.9-150000.3.23.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.