CVE-2019-9278: Integer Overflow
Published Sep 27, 2019
·Updated
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
Affected Software
14 affected componentsFixes available
debian/libexif<=0.6.21-5.1, <=0.6.21-2
0.6.21-60.6.21-5.1+deb10u10.6.21-2+deb9u1
Google Android=10.0
openSUSE Leap=15.1
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
debian/libexif
0.6.22-30.6.24-10.6.25-1
Remediation
Patch Available
Event History
Sep 27, 2019
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·06:03 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·06:04 PM
Description
Data Sourced
via Debian·06:04 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-9278.
2
What is the severity of CVE-2019-9278?
The severity of CVE-2019-9278 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software includes libexif versions 0.6.21-6, 0.6.21-5.1+deb10u1, and 0.6.21-2.
4
How can the vulnerability CVE-2019-9278 be fixed?
To fix CVE-2019-9278, update libexif to versions 0.6.21-5.1+deb10u5, 0.6.22-3, or 0.6.24-1.
5
Is user interaction required for exploitation of CVE-2019-9278?
Yes, user interaction is needed for exploitation of CVE-2019-9278.