Back

MEDIUM

libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c

Published May 14, 2020

Description

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published May 14, 2020
Updated Aug 4, 2024
Reserved Oct 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 4, 2020
ENISA EUVD
Assigner google_android
Published May 14, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-1600