imvips2dz in /libvips/libvips/deprecated/imvips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Function", "target": { "file": "libvips/deprecated/im_vips2dz.c", "function": "im_vips2dz" }, "id": "CVE-2020-20739-12027fd6", "digest": { "length": 1463.0, "function_hash": "166909256359593029980035354932831932721" }, "deprecated": false, "source": "https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "libvips/deprecated/im_vips2dz.c" }, "id": "CVE-2020-20739-ac65903d", "digest": { "line_hashes": [ "8760043487014167241584431414302043730", "171250312443488248624066404327138487390", "64839101584638378883248014138464275044", "228273560859497549535549242024299462680" ], "threshold": 0.9 }, "deprecated": false, "source": "https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a" } ] }