imvips2dz in /libvips/libvips/deprecated/imvips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
[
{
"deprecated": false,
"source": "https://github.com/libvips/libvips/commit/6ea76f9632edd93a716533acb78e7f6bd7089fe4",
"id": "CVE-2020-20739-45a6fd0e",
"target": {
"file": "libvips/foreign/jpeg2vips.c",
"function": "read_jpeg_header"
},
"digest": {
"function_hash": "222320631276143992629725486564266434665",
"length": 4038.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/libvips/libvips/commit/6ea76f9632edd93a716533acb78e7f6bd7089fe4",
"id": "CVE-2020-20739-9c4272ef",
"target": {
"file": "libvips/foreign/jpeg2vips.c"
},
"digest": {
"line_hashes": [
"125972106182712768501205550043563232520",
"86039469205557756946793548815830721573",
"88821371842791875340927780191313916485",
"77321317125073647324253898459710890524",
"154057355696739768365072229679567670185",
"244277135587429140701503486848767944083",
"21734349347026488473724128397556756436",
"9526486098358187007820695027713276441",
"216634604053247192044250025449613641808",
"286742946168779614417633791036156230208",
"234081553680285278521543908288125626223",
"77644325345481531206301909079295925322",
"58189127241607797732055871855340681054",
"127209824266690391183367214157703481504",
"262563188951938984018963082140095202961",
"36386234001265852768838143608841138472"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-20739.json"