VDB

CVE-2020-35535

CVE-2020-35535 PUBLISHED

In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.

EPSS 0.05% · 15.1th percentile

Risk Scores

EPSS Score
0.05%
15.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSexactimage1.0.2-5ubuntu2, 1.0.2-5ubuntu1, 0
Ubuntu:24.04:LTSdarktable4.4.2-1.1build1, 4.6.1-2build3, 4.6.1-2build4
Ubuntu:25.10kodi*, *, 0
Ubuntu:22.04:LTSkodi*, *, 2:19.3+dfsg1-1build3
Ubuntu:20.04:LTSkodi0, *, 2:18.6+dfsg1-2ubuntu1
Ubuntu:22.04:LTSdarktable3.8.1-1, 3.8.0-3, 3.8.0-3build2
Ubuntu:18.04:LTSexactimage1.0.1-1, 0.9.2-1build1, 0
Ubuntu:20.04:LTSdcraw9.28-2, 0
Ubuntu:16.04:LTSdcraw0, 9.21-0.2
Ubuntu:18.04:LTSdcraw9.27-1ubuntu1, 0
Ubuntu:18.04:LTSkodi2:17.6+dfsg1-1build1, 2:17.6+dfsg1-1ubuntu1, 0
Ubuntu:22.04:LTSdcraw0, 9.28-3, 9.28-2
Ubuntu:18.04:LTSdarktable2.4.0-1, 0, 2.2.5-2
Ubuntu:18.04:LTSrawtherapee0, 5.3-1, 5.2-1
Ubuntu:25.10rawtherapee0, 5.11-2build2
Ubuntu:16.04:LTSexactimage0, 0.9.1-6build1, 0.9.1-12
Ubuntu:16.04:LTSrawtherapee4.2-2build1, 4.2-4, 0
Ubuntu:24.04:LTSrawtherapee5.10-1build3, 5.10-1, 0
Ubuntu:22.04:LTSrawtherapee0, 5.8-3
Ubuntu:24.04:LTSexactimage1.0.2-11build4, 1.0.2-11build7, 1.0.2-11build3

…and 12 more

Timeline

  • Sep 1, 2022 CVE Published
  • Sep 2, 2022 EPSS Score
  • Oct 17, 2022 EPSS Score
  • Dec 2, 2022 EPSS Score
  • Jan 16, 2023 EPSS Score
  • Mar 2, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 17, 2023 EPSS Score
  • Jun 1, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
  • Aug 30, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›