Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
[
{
"id": "CVE-2020-36280-2711da70",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 4273.0,
"function_hash": "7304998107223771283968225551177814817"
},
"target": {
"function": "main",
"file": "prog/dewarptest1.c"
},
"source": "https://github.com/danbloomberg/leptonica/commit/5ba34b1fe741d69d43a6c8cf767756997eadd87c",
"signature_type": "Function"
},
{
"id": "CVE-2020-36280-2f27d4c9",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"87859225014807308672402855510697016471",
"247747152226049272958165541518093053454",
"39435067235498929049017845219139427745",
"203204699579402051083552990419479845226",
"130817942752224942924083283586337067206",
"102302979408446852464039475065439923522",
"336144749096136206594338358156604168754",
"111845197149690189529191472009466779890",
"318640266632657569097740050596364024000"
],
"threshold": 0.9
},
"target": {
"file": "prog/dewarptest1.c"
},
"source": "https://github.com/danbloomberg/leptonica/commit/5ba34b1fe741d69d43a6c8cf767756997eadd87c",
"signature_type": "Line"
},
{
"id": "CVE-2020-36280-4ff10216",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"143048840517715229491176562475832158693",
"197964211353547199732773998829495468748",
"107782724644974991147542262273421048736",
"248321617014896117935574148151650591234"
],
"threshold": 0.9
},
"target": {
"file": "src/tiffio.c"
},
"source": "https://github.com/danbloomberg/leptonica/commit/5ba34b1fe741d69d43a6c8cf767756997eadd87c",
"signature_type": "Line"
},
{
"id": "CVE-2020-36280-6deca786",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 6212.0,
"function_hash": "1081849412496552955681668456730730621"
},
"target": {
"function": "pixReadFromTiffStream",
"file": "src/tiffio.c"
},
"source": "https://github.com/danbloomberg/leptonica/commit/5ba34b1fe741d69d43a6c8cf767756997eadd87c",
"signature_type": "Function"
}
]