{"id":"CVE-2020-20739","details":"im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.","modified":"2026-03-14T10:19:54.415908Z","published":"2020-11-20T19:15:11.710Z","references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00049.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZULVPQQ4QDFSQCXFYBUXEM7UXJAOKLSP/"},{"type":"REPORT","url":"https://github.com/libvips/libvips/issues/1419"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"6ea76f9632edd93a716533acb78e7f6bd7089fe4"},{"fixed":"2ab5aa7bf515135c2b02d42e9a72e4c98e17031a"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"8.8.2"}]}}],"versions":["v7.28.0","v7.30.0","v8.0-beta","v8.1","v8.2.2","v8.2.3","v8.3.0","v8.4.2","v8.5.1","v8.5.2","v8.5.3","v8.5.4","v8.5.5","v8.5.6","v8.5.7","v8.5.8","v8.5.9","v8.6.0","v8.6.0-alpha1","v8.6.0-alpha2","v8.6.0-alpha3","v8.6.0-alpha4","v8.6.0-alpha5","v8.6.0-beta1","v8.6.0-beta2","v8.6.1","v8.6.2","v8.6.3","v8.6.4","v8.7.0","v8.7.0-alpha1","v8.7.0-alpha2","v8.7.0-rc1","v8.7.0-rc2","v8.7.0-rc3","v8.7.1","v8.7.2","v8.7.3","v8.7.4","v8.8.0","v8.8.0-rc1","v8.8.0-rc2","v8.8.0-rc3","v8.8.1"],"database_specific":{"vanir_signatures":[{"signature_type":"Function","id":"CVE-2020-20739-12027fd6","digest":{"function_hash":"166909256359593029980035354932831932721","length":1463},"deprecated":false,"target":{"file":"libvips/deprecated/im_vips2dz.c","function":"im_vips2dz"},"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a"},{"signature_type":"Function","id":"CVE-2020-20739-45a6fd0e","digest":{"function_hash":"222320631276143992629725486564266434665","length":4038},"deprecated":false,"target":{"file":"libvips/foreign/jpeg2vips.c","function":"read_jpeg_header"},"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/6ea76f9632edd93a716533acb78e7f6bd7089fe4"},{"signature_type":"Line","id":"CVE-2020-20739-9c4272ef","digest":{"line_hashes":["125972106182712768501205550043563232520","86039469205557756946793548815830721573","88821371842791875340927780191313916485","77321317125073647324253898459710890524","154057355696739768365072229679567670185","244277135587429140701503486848767944083","21734349347026488473724128397556756436","9526486098358187007820695027713276441","216634604053247192044250025449613641808","286742946168779614417633791036156230208","234081553680285278521543908288125626223","77644325345481531206301909079295925322","58189127241607797732055871855340681054","127209824266690391183367214157703481504","262563188951938984018963082140095202961","36386234001265852768838143608841138472"],"threshold":0.9},"deprecated":false,"target":{"file":"libvips/foreign/jpeg2vips.c"},"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/6ea76f9632edd93a716533acb78e7f6bd7089fe4"},{"signature_type":"Line","id":"CVE-2020-20739-ac65903d","digest":{"line_hashes":["8760043487014167241584431414302043730","171250312443488248624066404327138487390","64839101584638378883248014138464275044","228273560859497549535549242024299462680"],"threshold":0.9},"deprecated":false,"target":{"file":"libvips/deprecated/im_vips2dz.c"},"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a"}],"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"32"}]},{"events":[{"introduced":"0"},{"last_affected":"32"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-20739.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}