Описание
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 0.6.21-4ubuntu0.1 |
| devel | not-affected | 0.6.21-6 |
| disco | ignored | end of life |
| eoan | released | 0.6.21-5.1ubuntu0.1 |
| esm-infra-legacy/trusty | released | 0.6.21-1ubuntu1+esm1 |
| esm-infra/bionic | released | 0.6.21-4ubuntu0.1 |
| esm-infra/xenial | released | 0.6.21-2ubuntu0.1 |
| precise/esm | not-affected | 0.6.20-2ubuntu0.2 |
| trusty | ignored | end of standard support |
| trusty/esm | released | 0.6.21-1ubuntu1+esm1 |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
In libexif, there is a possible out of bounds write due to an integer ...
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
Уязвимость библиотеки для грамматического разбора EXIF-файлов libexif, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3