CVE-2020-0093

Publication date 14 May 2020

Last updated 11 July 2025


Ubuntu priority

Cvss 3 Severity Score

5.0 · Medium

Score breakdown

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details

Severity score breakdown

Parameter Value
Base score 5.0 · Medium
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

References

Related Ubuntu Security Notices (USN)

Other references