Back

MEDIUM

libexif: out of bounds read due to a missing bounds check in exif_entry_get_value function in exif-entry.c

Published Jun 11, 2020

Description

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147140917

Affected products

Remediation

Red Hat mitigation

This flaw could be mitigated by not passing untrusted input to libexif.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jun 11, 2020
Updated Aug 4, 2024
Reserved Oct 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 1, 2020
ENISA EUVD
Assigner google_android
Published Jun 11, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-1686