Back to Database
Status published
Medium
CVE-2020-20739
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized...
Vulnerability Description
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-20739
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/libvips/libvips/issues/1419
- https://github.com/libvips/libvips/commit/2ab5aa7bf515135c2b02d42e9a72e4c98e17031a
- https://lists.debian.org/debian-lts-announce/2020/11/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZULVPQQ4QDFSQCXFYBUXEM7UXJAOKLSP/
More from libvips
View All →CVE-2025-59933
libvips is vulnerable to Buffer Over-Read in poppler-based pdfload
Medium
5.1
CVE-2025-29769
libvips has a potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF output
High
8.5
CVE-2023-40032
Potential segfault due to NULL pointer dereference in libvips
Medium
5.5
CVE-2021-27847
Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83,...
Medium
6.5
CVE-2019-6976
libvips before 8.7.4 generates output images from uninitialized memory locations...
Medium
5.3
Affected Vendor
libvips
View all reports →Affected Software
libvips, debian linux, fedora
Vulnerable Versions:
0, 9.0, 32
Timeline
Official Publish:
November 20th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.