CVE-2020-0093: Medium severity Google Android vulnerability
In exifdatasavedataentry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-0093?
CVE-2020-0093 is a vulnerability that allows for a possible out of bounds read due to a missing bounds check.
What is the severity of CVE-2020-0093?
CVE-2020-0093 has a severity rating of high.
How can CVE-2020-0093 be exploited?
CVE-2020-0093 can be exploited through local information disclosure with no additional execution privileges needed, but requires user interaction.
Which products are affected by CVE-2020-0093?
Android versions 8.0, 8.1, 9.0, and 10.0 are affected by CVE-2020-0093, as well as the libexif package in Debian Linux and Ubuntu Linux.
How can I fix CVE-2020-0093?
To fix CVE-2020-0093, update the libexif package to version 0.6.21-5.1+deb10u5 or higher on Debian Linux, or version 0.6.21-4ubuntu0.5 or higher on Ubuntu Linux.