Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-5402

Опубликовано: 14 дек. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-5402: libexif security update (IMPORTANT)

[0.6.22-2]

  • Fix CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
  • Resolves: #1902589

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

libexif

0.6.22-2.el7_9

libexif-devel

0.6.22-2.el7_9

libexif-doc

0.6.22-2.el7_9

Oracle Linux x86_64

libexif

0.6.22-2.el7_9

libexif-devel

0.6.22-2.el7_9

libexif-doc

0.6.22-2.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

CVSS3: 9.8
redhat
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

CVSS3: 9.8
nvd
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

CVSS3: 9.8
debian
больше 4 лет назад

In exif_entry_get_value of exif-entry.c, there is a possible out of bo ...

rocky
больше 4 лет назад

Important: libexif security update