Medium severity5.5NVD Advisory· Published Sep 1, 2022· Updated Jun 17, 2026
CVE-2020-35532
CVE-2020-35532
Description
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:libraw:libraw:0.20.0:-:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:libraw:libraw:0.20.0:-:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.2:*:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.21.0:beta1:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3- github.com/LibRaw/LibRaw/commit/5ab45b085898e379fedc6b113e2e82a890602b1envdPatchThird Party Advisory
- github.com/LibRaw/LibRaw/issues/271nvdExploitIssue TrackingPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/09/msg00024.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.