VDB

CVE-2020-36280

CVE-2020-36280 PUBLISHED

Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.

EPSS 1.75% · 82.9th percentile

Risk Scores

EPSS Score
1.75%
82.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSleptonlib1.75.3-3, 1.75.3-3ubuntu0.1~esm1, 1.74.4-2
Ubuntu:Pro:16.04:LTSleptonlib1.73-1ubuntu0.1~esm1, 0, 1.72-3
Ubuntu:Pro:14.04:LTSleptonlib1.69-4ubuntu3, 1.70.1-1ubuntu0.1~esm1, 1.70.1-1
Ubuntu:22.04:LTSleptonlib0, 1.79.0-1.1, 1.82.0-3build1
Ubuntu:20.04:LTSleptonlib0, 1.79.0-1, 1.78.0-2

Timeline

  • Mar 12, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 12, 2021 EPSS Score
  • Dec 3, 2021 CVE Updated
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›