CVE-2020-0093
published 2020-05-14CVE-2020-0093: In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information…
PriorityP421medium5CVSS 3.1
AVLACLPRLUIRSUCHINAN
EPSS
0.30%
22.1th percentile
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libexif | < libexif 0.6.21-8 (bookworm) | libexif 0.6.21-8 (bookworm) |
| debian | libexif | < libexif 0.6.21-9 (bookworm) | libexif 0.6.21-9 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| libexif_project | libexif | < 0.6.22 | 0.6.22 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-8 | 0.6.21-8 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-8 | 0.6.21-8 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-8 | 0.6.21-8 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-8 | 0.6.21-8 |
| libexif_project | libexif | >= 0 < 0.6.21-2ubuntu0.5 | 0.6.21-2ubuntu0.5 |
| libexif_project | libexif | >= 0 < 0.6.21-4ubuntu0.5 | 0.6.21-4ubuntu0.5 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pxw-3px9-5fg9: An issue was discovered in libexif before 0
ghsa_unreviewed·2022-05-24·CVSS 5.0
CVE-2020-13112 [MEDIUM] CWE-125 GHSA-4pxw-3px9-5fg9: An issue was discovered in libexif before 0
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
GHSA
GHSA-cr92-4pr9-789r: In exif_data_save_data_entry of exif-data
ghsa_unreviewed·2022-05-24
CVE-2020-0093 [LOW] CWE-125 GHSA-cr92-4pr9-789r: In exif_data_save_data_entry of exif-data
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
OSV
libexif vulnerabilities
osv·2020-06-16·CVSS 5.0
CVE-2020-0093 [MEDIUM] libexif vulnerabilities
libexif vulnerabilities
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2020-0093, CVE-2020-0182)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a remote denial of service.
(CVE-2020-0198)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information or
cause a crash. (CVE-2020-13112)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2020-13113)
It was discovered libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a d
OSV
CVE-2020-13112: An issue was discovered in libexif before 0
osv·2020-05-21·CVSS 5.0
CVE-2020-13112 [MEDIUM] CVE-2020-13112: An issue was discovered in libexif before 0
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
OSV
CVE-2020-0093: In exif_data_save_data_entry of exif-data
osv·2020-05-14·CVSS 5.0
CVE-2020-0093 [MEDIUM] CVE-2020-0093: In exif_data_save_data_entry of exif-data
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2020-06-16·CVSS 5.0
CVE-2020-0093 [MEDIUM] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: Several security issues were fixed in libexif.
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2020-0093, CVE-2020-0182)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a remote denial of service.
(CVE-2020-0198)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information or
cause a crash. (CVE-2020-13112)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2020-13113)
It was discovered libexif incorrectly handled certai
Red Hat
libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
vendor_redhat·2020-05-16·CVSS 5.0
CVE-2020-13112 [MEDIUM] CWE-122 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
A heap-buffer out-of-bounds read flaw was found in libexif's MakerNote tag parser. This flaw allows an unauthenticated attacker or authenticated attacker with low privileges to exploit the flaw remotely in an application that uses libexif to process EXIF data from media files if the file upload is allowed. An attacker could create a specially crafted image file that, when processed by libexif, would cause the application to crash or, potentially expose data from the application's memory. This atta
Red Hat
libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
vendor_redhat·2020-05-04·CVSS 5.0
CVE-2020-0093 [MEDIUM] CWE-805 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
Package: libexif (Red Hat Enterprise Linux 5) - Out of support scope
Package: libexif (Red Hat Enterprise Linux 6) - Out of support scope
Android
CVE-2020-0093: Android Security Bulletin 2020-05-01
CVE: CVE-2020-0093
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-05-01·CVSS 5.0
CVE-2020-0093 [MEDIUM] CVE-2020-0093: Android Security Bulletin 2020-05-01
CVE: CVE-2020-0093
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-05-01
CVE: CVE-2020-0093
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-148705132
Debian
CVE-2020-0093: libexif - In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds r...
vendor_debian·2020·CVSS 5.0
CVE-2020-0093 [MEDIUM] CVE-2020-0093: libexif - In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds r...
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
Scope: local
bookworm: resolved (fixed in 0.6.21-8)
bullseye: resolved (fixed in 0.6.21-8)
forky: resolved (fixed in 0.6.21-8)
sid: resolved (fixed in 0.6.21-8)
trixie: resolved (fixed in 0.6.21-8)
Debian
CVE-2020-13112: libexif - An issue was discovered in libexif before 0.6.22. Several buffer over-reads in E...
vendor_debian·2020·CVSS 5.0
CVE-2020-13112 [MEDIUM] CVE-2020-13112: libexif - An issue was discovered in libexif before 0.6.22. Several buffer over-reads in E...
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Scope: local
bookworm: resolved (fixed in 0.6.21-9)
bullseye: resolved (fixed in 0.6.21-9)
forky: resolved (fixed in 0.6.21-9)
sid: resolved (fixed in 0.6.21-9)
trixie: resolved (fixed in 0.6.21-9)
Suricata
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0093 [HIGH] ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id DELETE
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id DELETE"; flow:established,to_server; http.uri; content:"/page.php?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2007-0093; reference:url,www.milw0rm.com/exploits/3076; classtype:web-application-attack; sid:2005874; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Ac
Suricata
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0093 [HIGH] ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UPDATE
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UPDATE"; flow:established,to_server; http.uri; content:"/page.php?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2007-0093; reference:url,www.milw0rm.com/exploits/3076; classtype:web-application-attack; sid:2005876; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Acc
Suricata
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0093 [HIGH] ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id SELECT
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id SELECT"; flow:established,to_server; http.uri; content:"/page.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2007-0093; reference:url,www.milw0rm.com/exploits/3076; classtype:web-application-attack; sid:2005871; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Ac
Suricata
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0093 [HIGH] ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UNION SELECT
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id UNION SELECT"; flow:established,to_server; http.uri; content:"/page.php?"; nocase; content:"id="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2007-0093; reference:url,www.milw0rm.com/exploits/3076; classtype:web-application-attack; sid:2005872; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_na
Suricata
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0093 [HIGH] ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id ASCII
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id ASCII"; flow:established,to_server; http.uri; content:"/page.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2007-0093; reference:url,www.milw0rm.com/exploits/3076; classtype:web-application-attack; sid:2005875; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_A
Suricata
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0093 [HIGH] ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id INSERT
ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Simple Web Content Management System SQL Injection Attempt -- page.php id INSERT"; flow:established,to_server; http.uri; content:"/page.php?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2007-0093; reference:url,www.milw0rm.com/exploits/3076; classtype:web-application-attack; sid:2005873; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Ac
No public exploits indexed.
Bugzilla
CVE-2020-0093 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
bugzilla·2020-06-30·CVSS 5.0
CVE-2020-0093 [MEDIUM] CVE-2020-0093 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
CVE-2020-0093 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
References:
https://source.android.com/security/bulletin/2020-05-01
https://android.googlesource.com/platform/external/libexif/+/0335ffc17f9b9a4831c242bb08ea92f605fde7a6
Discussion:
Created libexif tracking bugs for this issue:
Affects: fedora-all [bug 1852489]
---
Technical Summary:
In exif_data_save_data_entry(), data is copied using memcpy(), from e->data, using a size computation that relies on the stand
Bugzilla
CVE-2020-0093 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c [fedora-all]
bugzilla·2020-06-30·CVSS 5.0
CVE-2020-0093 [MEDIUM] CVE-2020-0093 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c [fedora-all]
CVE-2020-0093 libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit me
Bugzilla
CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
bugzilla·2020-05-26·CVSS 5.0
CVE-2020-13112 [MEDIUM] CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Reference and upstream commit:
https://github.com/libexif/libexif/commit/435e21f05001fb03f9f186fa7cbc69454afd00d1
Discussion:
Created libexif tracking bugs for this issue:
Affects: fedora-all [bug 1840345]
---
====Technical Summary====
The libexif library parses an EXIF tag called a MakerNote. According to the EXIF standard[1], a MakerNote tag can hold manufacturer-specific data from camera manufacturers such as Nikon, Olympus, Canon, Panasonic, etc... The vulnerable component
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2020/05/msg00016.htmlhttps://security.gentoo.org/glsa/202007-05https://source.android.com/security/bulletin/2020-05-01https://usn.ubuntu.com/4396-1/http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2020/05/msg00016.htmlhttps://security.gentoo.org/glsa/202007-05https://source.android.com/security/bulletin/2020-05-01https://usn.ubuntu.com/4396-1/
2020-05-14
Published