CVE-2020-0182

Priority
Description
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds
read due to a missing bounds check. This could lead to local information
disclosure with no additional execution privileges needed. User interaction
is not needed for exploitation.Product: AndroidVersions: Android-10Android
ID: A-147140917
Assigned-to
leosilva
Notes
Package
Upstream:released (0.6.22-1)
Ubuntu 12.04 ESM (Precise Pangolin):released (0.6.20-2ubuntu0.6)
Ubuntu 14.04 ESM (Trusty Tahr):released (0.6.21-1ubuntu1+esm5)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.6.21-2ubuntu0.5)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.6.21-4ubuntu0.5)
Ubuntu 19.10 (Eoan Ermine):released (0.6.21-5.1ubuntu0.5)
Ubuntu 20.04 LTS (Focal Fossa):released (0.6.21-6ubuntu0.3)
Ubuntu 20.10 (Groovy Gorilla):not-affected (0.6.22-1)
Patches:
Upstream:https://github.com/libexif/libexif/commit/f9bb9f263fb00f0603ecbefa8957cad24168cbff (0.6.22)
More Information

Updated: 2020-07-08 13:15:35 UTC (commit dea10fea942152490d34ca31e8745023d2cefc67)