CVE-2019-9278

Priority
Description
In libexif, there is a possible out of bounds write due to an integer
overflow. This could lead to remote escalation of privilege in the media
content provider with no additional execution privileges needed. User
interaction is needed for exploitation. Product: AndroidVersions:
Android-10Android ID: A-112537774
Assigned-to
leosilva
Notes
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):released (0.6.20-2ubuntu0.2)
Ubuntu 14.04 ESM (Trusty Tahr):released (0.6.21-1ubuntu1+esm1)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.6.21-2ubuntu0.1)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.6.21-4ubuntu0.1)
Ubuntu 19.10 (Eoan Ermine):released (0.6.21-5.1ubuntu0.1)
Ubuntu 20.04 (Focal Fossa):needed
Patches:
Vendor:https://android.googlesource.com/platform/external/libexif/+/a5e8e5812a11ec9686294de8a5d68aaf2ab72475
Upstream:https://github.com/libexif/libexif/commit/75aa73267fdb1e0ebfbc00369e7312bac43d0566
More Information

Updated: 2020-02-11 19:14:25 UTC (commit cf2d4dc25bf9031d6ac3454212992f5b0ff7ecac)