Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-5393

Опубликовано: 15 дек. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-5393: libexif security update (IMPORTANT)

[0.6.22-5]

  • Fix CVE-2020-0452
  • Resolves: #1902593

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libexif

0.6.22-5.el8_3

libexif-devel

0.6.22-5.el8_3

Oracle Linux x86_64

libexif

0.6.22-5.el8_3

libexif-devel

0.6.22-5.el8_3

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

CVSS3: 9.8
redhat
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

CVSS3: 9.8
nvd
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

CVSS3: 9.8
debian
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bo ...

rocky
больше 4 лет назад

Important: libexif security update