LibRaw: Multiple vulnerabilities Multiple vulnerabilities have been found in LibRaw, the worst of which may allow attackers to execute arbitrary code. libraw 2020-10-20 2020-10-20 744190 local, remote 0.20.0 0.20.0

LibRaw is a library for reading RAW files obtained from digital photo cameras.

Multiple vulnerabilities have been discovered in LibRaw. Please review the CVE identifiers referenced below for details.

A remote attacker could entice a user to open a specially crafted image file using an application linked against LibRaw, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All LibRaw users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/libraw-0.20.0"
CVE-2020-24889 CVE-2020-24890 sam_c whissi