CVE-2020-12767: Divide by Zero
exifentrygetvalue in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-12767?
CVE-2020-12767 is a vulnerability in libexif 0.6.21 that has a divide-by-zero error in the exif_entry_get_value function.
How severe is CVE-2020-12767?
CVE-2020-12767 has a severity rating of medium, with a CVSS score of 5.5.
Which versions of libexif are affected by CVE-2020-12767?
Versions 0.6.21-4ubuntu0.2, 0.6.21-5.1ubuntu0.2, 0.6.21-6ubuntu0.1, 0.6.21-1ubuntu1+, and 0.6.21-2ubuntu0.2 of libexif are affected by CVE-2020-12767.
How can I fix CVE-2020-12767?
To fix CVE-2020-12767, update libexif to version 0.6.21-4ubuntu0.2, 0.6.21-5.1ubuntu0.2, 0.6.21-6ubuntu0.1, 0.6.21-1ubuntu1+, or 0.6.21-2ubuntu0.2, depending on your Ubuntu distribution.
Where can I find more information about CVE-2020-12767?
You can find more information about CVE-2020-12767 in the following references: [GitHub issue](https://github.com/libexif/libexif/issues/31), [Debian LTS announcement](https://lists.debian.org/debian-lts-announce/2020/05/msg00016.html), [Ubuntu security notice](https://usn.ubuntu.com/4358-1/)