Medium severity5.5NVD Advisory· Published Sep 1, 2022· Updated Jun 17, 2026
CVE-2020-35534
CVE-2020-35534
Description
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:libraw:libraw:0.20.0:-:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:libraw:libraw:0.20.0:-:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.20.2:*:*:*:*:*:*:*
- cpe:2.3:a:libraw:libraw:0.21.0:beta1:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- github.com/LibRaw/LibRaw/commit/e41f331e90b383e3208cefb74e006df44bf3a4b8nvdPatchThird Party Advisory
- github.com/LibRaw/LibRaw/issues/279nvdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.