Unrated severityNVD Advisory· Published Feb 17, 2023· Updated Mar 19, 2025
CVE-2021-32142
CVE-2021-32142
Description
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.
Affected products
8- LibRaw/LibRawdescription
- osv-coords7 versionspkg:rpm/almalinux/LibRawpkg:rpm/almalinux/LibRaw-develpkg:rpm/opensuse/libraw&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/libraw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4
< 0.20.2-6.el9+ 6 more
- (no CPE)range: < 0.20.2-6.el9
- (no CPE)range: < 0.20.2-6.el9
- (no CPE)range: < 0.18.9-150000.3.17.1
- (no CPE)range: < 0.20.2-150400.3.3.1
- (no CPE)range: < 0.15.4-36.1
- (no CPE)range: < 0.15.4-36.1
- (no CPE)range: < 0.18.9-150000.3.17.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E7TEZ7CLRNYYQZJ5NJGZXK6YJU46WH2L/mitrevendor-advisory
- www.debian.org/security/2023/dsa-5412mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/05/msg00025.htmlmitremailing-list
- github.com/LibRaw/LibRaw/commit/bc3aaf4223fdb70d52d470dae65c5a7923ea2a49mitre
- github.com/LibRaw/LibRaw/issues/400mitre
- www.libraw.orgmitre
News mentions
0No linked articles in our index yet.