Security Advisory

CVE-2020-24890

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-09-16 14:39:49
Last updated 2024-08-04 15:19:09
Assigner mitre
State PUBLISHED

Description

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way