In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.20.2-2ubuntu2", "binary_name": "libraw-bin" }, { "binary_version": "0.20.2-2ubuntu2", "binary_name": "libraw-bin-dbgsym" }, { "binary_version": "0.20.2-2ubuntu2", "binary_name": "libraw-dev" }, { "binary_version": "0.20.2-2ubuntu2", "binary_name": "libraw-doc" }, { "binary_version": "0.20.2-2ubuntu2", "binary_name": "libraw20" }, { "binary_version": "0.20.2-2ubuntu2", "binary_name": "libraw20-dbgsym" } ], "availability": "No subscription required" }