First published: Thu May 21 2020(Updated: )
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libexif | 0.6.22-3 0.6.24-1 | |
libexif | <0.6.22 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
Ubuntu Linux | =20.04 | |
openSUSE | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13114 is a vulnerability in libexif before version 0.6.22 that allows for unrestricted size in handling Canon EXIF MakerNote data, leading to excessive computational resource consumption when decoding EXIF data.
The severity of CVE-2020-13114 is high, with a severity value of 7.5.
If you are using a version of libexif before 0.6.22, you may be vulnerable to CVE-2020-13114, which could result in excessive consumption of compute resources when decoding EXIF data.
To fix CVE-2020-13114, you should update libexif to version 0.6.22 or later. Check the official Ubuntu or Debian security notices for specific package versions and remedies.
You can find more information about CVE-2020-13114 on the MITRE CVE database, Ubuntu security notices, and the NIST National Vulnerability Database.