First published: Thu May 21 2020(Updated: )
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libexif Project Libexif | <0.6.22 | |
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
openSUSE Leap | =15.1 | |
Google Android | ||
debian/libexif | 0.6.22-3 0.6.24-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13112 is a vulnerability in libexif before version 0.6.22 that allows for buffer over-reads in EXIF MakerNote handling, leading to information disclosure and crashes.
CVE-2020-13112 has a severity rating of 9.1 (critical).
The affected software versions include libexif 0.6.21-4ubuntu0.5, 0.6.21-5.1ubuntu0.5, 0.6.21-6ubuntu0.3, 0.6.21-1ubuntu1+, and 0.6.21-2ubuntu0.5.
To fix CVE-2020-13112, update your libexif package to version 0.6.22 or higher.
You can find more information about CVE-2020-13112 at the following references: [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13112), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-4396-1), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-13112).