Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
[
{
"source": "https://github.com/danbloomberg/leptonica/commit/5ee24b398bb67666f6d173763eaaedd9c36fb1e5",
"target": {
"function": "pixFewColorsOctcubeQuantMixed",
"file": "src/colorquant1.c"
},
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2020-36281-2a31c4bf",
"digest": {
"function_hash": "137720579056761129431122090688794822280",
"length": 2230.0
},
"signature_type": "Function"
},
{
"source": "https://github.com/danbloomberg/leptonica/commit/5ee24b398bb67666f6d173763eaaedd9c36fb1e5",
"target": {
"file": "src/colorquant1.c"
},
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2020-36281-8673505a",
"digest": {
"line_hashes": [
"235192948415574869261478969795863729665",
"88535004939424933844178503462582762294",
"141798957895417634311087600950342099689",
"30732697983296527819897672159956548443",
"47564440560045519040319772547856215622",
"135724435681094057024484866105448360916",
"205891709256487112822424975114785007185",
"222247342120702118308525358050660833558",
"75358991503455113481714351445446229776"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]