VDB

CVE-2020-35534

CVE-2020-35534 PUBLISHED

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

EPSS 0.06% · 17.7th percentile

Risk Scores

EPSS Score
0.06%
17.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSkodi*, *, 0
Ubuntu:22.04:LTSrawtherapee5.8-3, 0
Ubuntu:18.04:LTSexactimage1.0.1-1, 0.9.2-1build1, 0
Ubuntu:20.04:LTSrawtherapee0, 5.6-1, 5.8-1
Ubuntu:25.10darktable5.0.1-0ubuntu1, 5.0.1-0ubuntu2, 5.0.1-1
Ubuntu:20.04:LTSkodi2:17.6+dfsg1-4ubuntu9, *, 2:18.5+dfsg1-0ubuntu3
Ubuntu:20.04:LTSdcraw9.28-2, 0
Ubuntu:16.04:LTSdarktable0, 1.6.9-1, 1.6.8-1
Ubuntu:18.04:LTSrawtherapee0, 5.2-1, 5.3-1
Ubuntu:24.04:LTSdarktable4.4.2-1.1, 4.6.1-2build3, 4.6.1-2
Ubuntu:24.04:LTSkodi0, 2:20.2+dfsg-4, 2:20.2+dfsg-4build1
Ubuntu:20.04:LTSexactimage1.0.2-3, 1.0.2-5ubuntu2, 1.0.2-7ubuntu1
Ubuntu:16.04:LTSrawtherapee0, 4.2-4, 4.2-2build1
Ubuntu:22.04:LTSexactimage0, 1.0.2-8build2, 1.0.2-8build3
Ubuntu:18.04:LTSkodi2:17.3+dfsg1-5build1, *, *
Ubuntu:20.04:LTSdarktable3.0.1-0ubuntu1, 0, 2.6.0-1
Ubuntu:24.04:LTSexactimage1.0.2-11build4, 1.0.2-11build8, 1.0.2-11build9
Ubuntu:16.04:LTSexactimage0.9.1-6ubuntu1, 0.9.1-9, 0.9.1-9build1
Ubuntu:16.04:LTSdcraw9.21-0.2, 0
Ubuntu:24.04:LTSrawtherapee5.9-1build1, 5.10-1build4, 5.10-1

…and 12 more

Timeline

  • Sep 1, 2022 CVE Published
  • Sep 2, 2022 EPSS Score
  • Oct 17, 2022 EPSS Score
  • Dec 2, 2022 EPSS Score
  • Jan 16, 2023 EPSS Score
  • Mar 2, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 17, 2023 EPSS Score
  • Jun 1, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
  • Aug 30, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›