CVE-2021-32142
Summary
| CVE | CVE-2021-32142 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-17 18:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: mingw-LibRaw-0.20.2-8.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| stack-buffer-over in libRaw · Issue #400 · LibRaw/LibRaw · GitHub | MISC | github.com | |
| check for input buffer size on datastream::gets · LibRaw/LibRaw@bc3aaf4 · GitHub | MISC | github.com | |
| Debian -- Security Information -- DSA-5412-1 libraw | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 36 Update: mingw-LibRaw-0.20.2-8.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| gtt1995 (taotao gu) · GitHub | MISC | github.com | |
| [SECURITY] Fedora 36 Update: mingw-LibRaw-0.20.2-8.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: mingw-LibRaw-0.20.2-8.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| About LibRaw | LibRaw | MISC | www.libraw.org | |
| [SECURITY] [DLA 3433-1] libraw security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161130 Oracle Enterprise Linux Security Update for libraw (ELSA-2023-6343)
- 161306 Oracle Enterprise Linux Security Update for libraw (ELSA-2024-0343)
- 181806 Debian Security Update for libraw (DLA 3433-1)
- 181809 Debian Security Update for libraw (DSA 5412-1)
- 184434 Debian Security Update for libraw (CVE-2021-32142)
- 199394 Ubuntu Security Notification for LibRaw Vulnerabilities (USN-6137-1)
- 242334 Red Hat Update for libraw (RHSA-2023:6343)
- 242735 Red Hat Update for libraw (RHSA-2024:0343)
- 257298 CentOS Security Update for LibRaw (CESA-2024:0343)
- 283787 Fedora Security Update for mingw (FEDORA-2023-be842ba7fb)
- 283788 Fedora Security Update for mingw (FEDORA-2023-220878f1bf)
- 356139 Amazon Linux Security Advisory for LibRaw : ALAS2-2023-2256
- 379350 Alibaba Cloud Linux Security Update for libraw (ALINUX2-SA-2024:0008)
- 753788 SUSE Enterprise Linux Security Update for libraw (SUSE-SU-2023:0510-1)
- 941361 AlmaLinux Security Update for LibRaw (ALSA-2023:6343)