{"id":"CVE-2020-36280","details":"Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.","modified":"2026-05-15T12:04:07.049393199Z","published":"2021-03-12T00:15:12.787Z","database_specific":{"unresolved_ranges":[{"vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"],"source":"CPE_FIELD","extracted_events":[{"last_affected":"32"},{"last_affected":"33"}]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQUEA2X6UTH4DMYCMZAWE2QQLN5YANUA/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RD5AIWHWE334HGYZJR2U3I3JYKSSO2LW/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202107-53"},{"type":"FIX","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=23654"},{"type":"FIX","url":"https://github.com/DanBloomberg/leptonica/commit/5ba34b1fe741d69d43a6c8cf767756997eadd87c"},{"type":"FIX","url":"https://github.com/DanBloomberg/leptonica/compare/1.79.0...1.80.0"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}