Information disclosure in libvips - CVE-2020-20739
Published: November 20, 2020 / Updated: December 1, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in "im_vips2dz" in "/libvips/libvips/deprecated/im_vips2dz.c". A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Ubuntu
Fedora
gir1.2-vips-8.0 (Ubuntu package)
libvips-tools (Ubuntu package)
libvips42 (Ubuntu package)
python-vipscc (Ubuntu package)
vips
How to mitigate CVE-2020-20739
gir1.2-vips-8.0 (Ubuntu package) - update to Ubuntu Pro
libvips-tools (Ubuntu package) - update to Ubuntu Pro
libvips42 (Ubuntu package) - update to Ubuntu Pro
python-vipscc (Ubuntu package) - update to Ubuntu Pro
vips - update to 8.8.4-5.fc32