Bugzilla – Bug 1176690
VUL-0: CVE-2020-24889: libraw: buffer overflow in LibRaw:GetNormalizedModel
Last modified: 2020-09-25 08:03:04 UTC
CVE-2020-24889 A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-24889 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24889 https://github.com/LibRaw/LibRaw/issues/334
SUSE:SLE-12:Update Not affected SUSE:SLE-15:Update Not affected openSUSE:Factory Affected
Wolfgang, thanks for analysis. Paolo have submitted 0.20.0 into factory already.