Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-12500

CVE-2020-22628: Out of bounds read in LibRaw::stretch() function

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • rhel-8.8.0, CentOS Stream 8
    • LibRaw
    • None
    • None
    • None
    • rhel-sst-display-productivity
    • ssg_display
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • All
    • None

      This CVE was reported against LibRaw-epel which just provides the missing development subpackages from LibRaw that are not shipped on some architectures:

      https://bugzilla.redhat.com/show_bug.cgi?id=2235275

       

      Debian's CVE page has more useful details - https://security-tracker.debian.org/tracker/CVE-2020-22628

       

      This is basically fixed in 0.20-RC2 so if EL8 is not going to get rebased the fix needs to be cherry picked

              dray@redhat.com Debarshi Ray
              michel.lind Michel Lind
              Debarshi Ray Debarshi Ray
              Tomas Pelka Tomas Pelka
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: