First published: Sat May 09 2020(Updated: )
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libexif | 0.6.22-3 0.6.24-1 | |
libexif | =0.6.21 | |
Debian Debian Linux | =8.0 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
Ubuntu Linux | =20.04 | |
openSUSE | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12767 is a vulnerability in libexif 0.6.21 that has a divide-by-zero error in the exif_entry_get_value function.
CVE-2020-12767 has a severity rating of medium, with a CVSS score of 5.5.
Versions 0.6.21-4ubuntu0.2, 0.6.21-5.1ubuntu0.2, 0.6.21-6ubuntu0.1, 0.6.21-1ubuntu1+, and 0.6.21-2ubuntu0.2 of libexif are affected by CVE-2020-12767.
To fix CVE-2020-12767, update libexif to version 0.6.21-4ubuntu0.2, 0.6.21-5.1ubuntu0.2, 0.6.21-6ubuntu0.1, 0.6.21-1ubuntu1+, or 0.6.21-2ubuntu0.2, depending on your Ubuntu distribution.
You can find more information about CVE-2020-12767 in the following references: [GitHub issue](https://github.com/libexif/libexif/issues/31), [Debian LTS announcement](https://lists.debian.org/debian-lts-announce/2020/05/msg00016.html), [Ubuntu security notice](https://usn.ubuntu.com/4358-1/)