CVE-2020-0198: Integer Overflow
In exifdataloaddatacontent of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-0198.
What is the severity of CVE-2020-0198?
The severity of CVE-2020-0198 is high with a severity value of 7.5 out of 10.
How does CVE-2020-0198 occur?
CVE-2020-0198 occurs due to an integer overflow in the exif_data_load_data_content function of exif-data.c.
What is the impact of CVE-2020-0198?
The impact of CVE-2020-0198 is a possible UBSAN abort, leading to remote denial of service with no additional execution privileges needed.
How can I fix CVE-2020-0198?
To fix CVE-2020-0198, update the libexif package to version 0.6.21-5.1+deb10u5, 0.6.22-3, or 0.6.24-1.