Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2020-0452

Published: 6 November 2020

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

Priority

Medium

Cvss 3 Severity Score

9.8

Score breakdown

Status

Package Release Status
libexif
Launchpad, Ubuntu, Debian
trusty
Released (0.6.21-1ubuntu1+esm6)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
xenial
Released (0.6.21-2ubuntu0.6)
bionic
Released (0.6.21-4ubuntu0.6)
focal
Released (0.6.21-6ubuntu0.4)
groovy
Released (0.6.22-2ubuntu0.1)
upstream Needs triage

Patches:
upstream: https://github.com/libexif/libexif/commit/9266d14b5ca4e29b970fa03272318e5f99386e06

Severity score breakdown

Parameter Value
Base score 9.8
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H