CVE-2020-13112: Critical severity Google Android vulnerability
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13112?
CVE-2020-13112 is a vulnerability in libexif before version 0.6.22 that allows for buffer over-reads in EXIF MakerNote handling, leading to information disclosure and crashes.
How severe is CVE-2020-13112?
CVE-2020-13112 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2020-13112?
The affected software versions include libexif 0.6.21-4ubuntu0.5, 0.6.21-5.1ubuntu0.5, 0.6.21-6ubuntu0.3, 0.6.21-1ubuntu1+, and 0.6.21-2ubuntu0.5.
How can I fix CVE-2020-13112?
To fix CVE-2020-13112, update your libexif package to version 0.6.22 or higher.
Where can I find more information about CVE-2020-13112?
You can find more information about CVE-2020-13112 at the following references: [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13112), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-4396-1), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-13112).