CVE-2020-0093

Priority
Description
In exif_data_save_data_entry of exif-data.c, there is a possible out of
bounds read due to a missing bounds check. This could lead to local
information disclosure with no additional execution privileges needed. User
interaction is needed for exploitation.Product: AndroidVersions:
Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
Assigned-to
leosilva
Notes
Package
Upstream:released (0.6.21-8)
Ubuntu 12.04 ESM (Precise Pangolin):released (0.6.20-2ubuntu0.6)
Ubuntu 14.04 ESM (Trusty Tahr):released (0.6.21-1ubuntu1+esm5)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.6.21-2ubuntu0.5)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.6.21-4ubuntu0.5)
Ubuntu 19.10 (Eoan Ermine):released (0.6.21-5.1ubuntu0.5)
Ubuntu 20.04 LTS (Focal Fossa):released (0.6.21-6ubuntu0.3)
Ubuntu 20.10 (Groovy Gorilla):not-affected (0.6.21-8)
Patches:
Upstream:https://github.com/libexif/libexif/commit/5ae5973bed1947f4d447dc80b76d5cefadd90133
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.10 (Eoan Ermine):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):needs-triage
Ubuntu 20.10 (Groovy Gorilla):needs-triage
More Information

Updated: 2020-06-16 15:14:36 UTC (commit bcd5d787f336a604cfddb07471014c8e7c0b2565)