imvips2dz in /libvips/libvips/deprecated/imvips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
}
]
[
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2020-20739-12027fd6",
"target": {
"file": "libvips/deprecated/im_vips2dz.c",
"function": "im_vips2dz"
},
"digest": {
"length": 1463.0,
"function_hash": "166909256359593029980035354932831932721"
},
"signature_version": "v1",
"source": "https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a"
},
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2020-20739-45a6fd0e",
"target": {
"file": "libvips/foreign/jpeg2vips.c",
"function": "read_jpeg_header"
},
"digest": {
"length": 4038.0,
"function_hash": "222320631276143992629725486564266434665"
},
"signature_version": "v1",
"source": "https://github.com/libvips/libvips/commit/6ea76f9632edd93a716533acb78e7f6bd7089fe4"
},
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2020-20739-9c4272ef",
"target": {
"file": "libvips/foreign/jpeg2vips.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"125972106182712768501205550043563232520",
"86039469205557756946793548815830721573",
"88821371842791875340927780191313916485",
"77321317125073647324253898459710890524",
"154057355696739768365072229679567670185",
"244277135587429140701503486848767944083",
"21734349347026488473724128397556756436",
"9526486098358187007820695027713276441",
"216634604053247192044250025449613641808",
"286742946168779614417633791036156230208",
"234081553680285278521543908288125626223",
"77644325345481531206301909079295925322",
"58189127241607797732055871855340681054",
"127209824266690391183367214157703481504",
"262563188951938984018963082140095202961",
"36386234001265852768838143608841138472"
]
},
"signature_version": "v1",
"source": "https://github.com/libvips/libvips/commit/6ea76f9632edd93a716533acb78e7f6bd7089fe4"
},
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2020-20739-ac65903d",
"target": {
"file": "libvips/deprecated/im_vips2dz.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"8760043487014167241584431414302043730",
"171250312443488248624066404327138487390",
"64839101584638378883248014138464275044",
"228273560859497549535549242024299462680"
]
},
"signature_version": "v1",
"source": "https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-20739.json"