Medium severity5.5NVD Advisory· Published Sep 1, 2022· Updated Jun 17, 2026
CVE-2020-35530
CVE-2020-35530
Description
In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:libraw:libraw:0.20.0:-:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:libraw:libraw:0.20.0:-:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.2:*:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.21.0:beta1:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3- github.com/LibRaw/LibRaw/commit/11c4db253ef2c9bb44247b578f5caa57c66a1eebnvdPatchThird Party Advisory
- github.com/LibRaw/LibRaw/issues/272nvdExploitIssue TrackingPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/09/msg00024.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.