Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
UBUNTU-CVE-2020-36278
See a problem?
Please try reporting it
to the source
first.
Source
https://ubuntu.com/security/CVE-2020-36278
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36278.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-36278
Upstream
CVE-2020-36278
Published
2021-03-12T00:15:00Z
Modified
2025-07-16T08:15:16.044991Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Ubuntu - medium
Summary
[none]
Details
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
References
https://ubuntu.com/security/CVE-2020-36278
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=23433
https://github.com/DanBloomberg/leptonica/commit/8d6e1755518cfb98536d6c3daf0601f226d16842
https://github.com/DanBloomberg/leptonica/compare/1.79.0...1.80.0
https://www.cve.org/CVERecord?id=CVE-2020-36278
Affected packages
Ubuntu:Pro:14.04:LTS
/
leptonlib
Package
Name
leptonlib
Purl
pkg:deb/ubuntu/leptonlib@1.70.1-1ubuntu0.1~esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.69-4ubuntu1
1.69-4ubuntu2
1.69-4ubuntu3
1.69-4ubuntu4
1.70.1-1
1.70.1-1ubuntu0.1~esm1
Ubuntu:Pro:16.04:LTS
/
leptonlib
Package
Name
leptonlib
Purl
pkg:deb/ubuntu/leptonlib@1.73-1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.72-3
1.72-3build1
1.73-1
1.73-1ubuntu0.1~esm1
Ubuntu:Pro:18.04:LTS
/
leptonlib
Package
Name
leptonlib
Purl
pkg:deb/ubuntu/leptonlib@1.75.3-3ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.74.4-1
1.74.4-2
1.75.3-1
1.75.3-2
1.75.3-3
1.75.3-3ubuntu0.1~esm1
Ubuntu:Pro:20.04:LTS
/
leptonlib
Package
Name
leptonlib
Purl
pkg:deb/ubuntu/leptonlib@1.79.0-1?arch=source&distro=esm-apps/focal
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.78.0-2
1.79.0-1
Ubuntu:22.04:LTS
/
leptonlib
Package
Name
leptonlib
Purl
pkg:deb/ubuntu/leptonlib@1.82.0-3build1?arch=source&distro=jammy
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Affected versions
1.*
1.79.0-1.1
1.82.0-3
1.82.0-3build1
UBUNTU-CVE-2020-36278 - OSV