CVE-2020-0182: Medium severity Google Android vulnerability
In exifentrygetvalue of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147140917
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-0182?
CVE-2020-0182 is a vulnerability in the libexif library in Android, Debian, and Ubuntu that allows for local information disclosure without additional execution privileges.
How severe is CVE-2020-0182?
CVE-2020-0182 has a severity rating of 6.5 (Medium).
How does CVE-2020-0182 affect Android?
Android versions up to and including Android-10 are affected by CVE-2020-0182.
How can I fix CVE-2020-0182 on Debian?
To fix CVE-2020-0182 on Debian, update the libexif package to version 0.6.21-5.1+deb10u5, 0.6.22-3, or 0.6.24-1.
How can I fix CVE-2020-0182 on Ubuntu?
To fix CVE-2020-0182 on Ubuntu, update the libexif package to version 0.6.21-6ubuntu0.3 for focal, 0.6.21-4ubuntu0.5 for bionic, 0.6.21-5.1ubuntu0.5 for eoan, 0.6.21-1ubuntu1+ for trusty, 0.6.22-1 for upstream, or 0.6.21-2ubuntu0.5 for xenial.