vulnerability

Oracle Linux: CVE-2020-24870: ELSA-2021-4381: GNOME security, bug fix, and enhancement update (MODERATE)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Aug 19, 2020
Added
Nov 17, 2021
Modified
Dec 3, 2025

Description

Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
A stack buffer overflow vulnerability was found in LibRaw. This flaw allows a malicious user to send a crafted image that, when parsed by an application linked to LibRaw, leads to a denial of service or potential code execution.

Solutions

oracle-linux-upgrade-accountsserviceoracle-linux-upgrade-accountsservice-develoracle-linux-upgrade-accountsservice-libsoracle-linux-upgrade-gdmoracle-linux-upgrade-gnome-autoaroracle-linux-upgrade-gnome-calculatororacle-linux-upgrade-gnome-classic-sessionoracle-linux-upgrade-gnome-control-centeroracle-linux-upgrade-gnome-control-center-filesystemoracle-linux-upgrade-gnome-online-accountsoracle-linux-upgrade-gnome-online-accounts-develoracle-linux-upgrade-gnome-sessionoracle-linux-upgrade-gnome-session-kiosk-sessionoracle-linux-upgrade-gnome-session-wayland-sessionoracle-linux-upgrade-gnome-session-xsessionoracle-linux-upgrade-gnome-settings-daemonoracle-linux-upgrade-gnome-shelloracle-linux-upgrade-gnome-shell-extension-apps-menuoracle-linux-upgrade-gnome-shell-extension-auto-move-windowsoracle-linux-upgrade-gnome-shell-extension-commonoracle-linux-upgrade-gnome-shell-extension-dash-to-dockoracle-linux-upgrade-gnome-shell-extension-desktop-iconsoracle-linux-upgrade-gnome-shell-extension-disable-screenshieldoracle-linux-upgrade-gnome-shell-extension-drive-menuoracle-linux-upgrade-gnome-shell-extension-gesture-inhibitororacle-linux-upgrade-gnome-shell-extension-horizontal-workspacesoracle-linux-upgrade-gnome-shell-extension-launch-new-instanceoracle-linux-upgrade-gnome-shell-extension-native-window-placementoracle-linux-upgrade-gnome-shell-extension-no-hot-corneroracle-linux-upgrade-gnome-shell-extension-panel-favoritesoracle-linux-upgrade-gnome-shell-extension-places-menuoracle-linux-upgrade-gnome-shell-extension-screenshot-window-sizeroracle-linux-upgrade-gnome-shell-extension-systemmonitororacle-linux-upgrade-gnome-shell-extension-top-iconsoracle-linux-upgrade-gnome-shell-extension-updates-dialogoracle-linux-upgrade-gnome-shell-extension-user-themeoracle-linux-upgrade-gnome-shell-extension-window-grouperoracle-linux-upgrade-gnome-shell-extension-window-listoracle-linux-upgrade-gnome-shell-extension-windowsnavigatororacle-linux-upgrade-gnome-shell-extension-workspace-indicatororacle-linux-upgrade-gnome-softwareoracle-linux-upgrade-gnome-software-develoracle-linux-upgrade-gsettings-desktop-schemasoracle-linux-upgrade-gsettings-desktop-schemas-develoracle-linux-upgrade-gtk3oracle-linux-upgrade-gtk3-develoracle-linux-upgrade-gtk3-immodule-ximoracle-linux-upgrade-gtk-update-icon-cacheoracle-linux-upgrade-libraworacle-linux-upgrade-libraw-develoracle-linux-upgrade-mutteroracle-linux-upgrade-mutter-develoracle-linux-upgrade-vinooracle-linux-upgrade-webkit2gtk3oracle-linux-upgrade-webkit2gtk3-develoracle-linux-upgrade-webkit2gtk3-jscoracle-linux-upgrade-webkit2gtk3-jsc-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.