Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-0093

Опубликовано: 14 мая 2020
Источник: debian
EPSS Низкий

Описание

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libexiffixed0.6.21-8package
libexiffixed0.6.21-5.1+deb10u2busterpackage
libexiffixed0.6.21-2+deb9u2stretchpackage

Примечания

  • https://github.com/libexif/libexif/issues/42

  • https://github.com/libexif/libexif/commit/5ae5973bed1947f4d447dc80b76d5cefadd90133

EPSS

Процентиль: 32%
0.00127
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
больше 5 лет назад

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

CVSS3: 5
redhat
почти 6 лет назад

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

CVSS3: 5
nvd
больше 5 лет назад

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

CVSS3: 5
github
больше 3 лет назад

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

CVSS3: 5
fstec
почти 6 лет назад

Уязвимость функции exif_data_save_data_entry() компонента exif-data.c библиотеки для грамматического разбора EXIF-файлов Libexif, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 32%
0.00127
Низкий