CVE-2020-13114: High severity Libexif Project Libexif vulnerability
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13114?
CVE-2020-13114 is a vulnerability in libexif before version 0.6.22 that allows for unrestricted size in handling Canon EXIF MakerNote data, leading to excessive computational resource consumption when decoding EXIF data.
What is the severity of CVE-2020-13114?
The severity of CVE-2020-13114 is high, with a severity value of 7.5.
How does CVE-2020-13114 affect me?
If you are using a version of libexif before 0.6.22, you may be vulnerable to CVE-2020-13114, which could result in excessive consumption of compute resources when decoding EXIF data.
How can I fix CVE-2020-13114?
To fix CVE-2020-13114, you should update libexif to version 0.6.22 or later. Check the official Ubuntu or Debian security notices for specific package versions and remedies.
Where can I find more information about CVE-2020-13114?
You can find more information about CVE-2020-13114 on the MITRE CVE database, Ubuntu security notices, and the NIST National Vulnerability Database.