Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identifyprocessdng_fields in identify.cpp.
{ "vanir_signatures": [ { "target": { "file": "src/metadata/identify.cpp" }, "digest": { "line_hashes": [ "127369863400399030445089453515086710742", "143352257161882419934463851685344218790", "149081386631648574687993847631526607820", "90571716103714361609775829094938631250", "64212602395394805498333815964493822952", "246029732494002346913498674344628261452", "336613780886055486036551309628972026859", "80819173922190116192470406883009366994", "83650079410275834961759166175003361250", "72611878404799344344766699135947092279", "184054827936135119807788380588696604905", "159345781273529265670087347869271034565", "46668523762482181852934340781690791223", "30895639349609606990868918680604187306", "193962300235662687148425839430341672206", "248672851197025629570687067468774085258", "323324160718181615062772601288014836379", "290007040198435070387284445091957484722", "201019683317171841142185943256224757142" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/libraw/libraw/commit/4feaed4dea636cee4fee010f615881ccf76a096d", "id": "CVE-2020-24870-31872964", "signature_type": "Line", "deprecated": false }, { "target": { "file": "src/metadata/identify.cpp", "function": "LibRaw::identify_process_dng_fields" }, "digest": { "length": 10660.0, "function_hash": "94799694404746039246306392899922980268" }, "signature_version": "v1", "source": "https://github.com/libraw/libraw/commit/4feaed4dea636cee4fee010f615881ccf76a096d", "id": "CVE-2020-24870-3f6d4e07", "signature_type": "Function", "deprecated": false } ] }