ALINUX2-SA-2020%3A0157
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-9278: In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774 CVE-2020-0093: In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132 CVE-2020-0182: In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147140917 CVE-2020-12767: exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. CVE-2020-13113: An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions. CVE-2020-13114: An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | libexif |
Timeline
- Oct 11, 2020 CVE Updated
- Oct 12, 2020 CVE Published
References
- ALINUX2-SA-2020:0157: libexif security, bug fix, and enhancement update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9278 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0093 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0182 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12767 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13113 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13114 advisory