Bug 1176690 - (CVE-2020-24889) VUL-0: CVE-2020-24889: libraw: buffer overflow in LibRaw:GetNormalizedModel
(CVE-2020-24889)
VUL-0: CVE-2020-24889: libraw: buffer overflow in LibRaw:GetNormalizedModel
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security
Current
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/267550/
CVSSv3.1:SUSE:CVE-2020-24889:5.9:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-09-17 18:35 UTC by Wolfgang Frisch
Modified: 2020-09-25 08:03 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-09-17 18:35:31 UTC
CVE-2020-24889

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-24889
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24889
https://github.com/LibRaw/LibRaw/issues/334
Comment 1 Wolfgang Frisch 2020-09-17 18:41:39 UTC
SUSE:SLE-12:Update  Not affected
SUSE:SLE-15:Update  Not affected
openSUSE:Factory    Affected
Comment 2 Petr Gajdos 2020-09-25 08:01:57 UTC
Wolfgang, thanks for analysis.

Paolo have submitted 0.20.0 into factory already.