Beveiligingsadvies

CVE-2020-24890

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-09-16 14:39:49
Laatst bijgewerkt 2024-08-04 15:19:09
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way