CVE-2020-13112
published 2020-05-21CVE-2020-13112: An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
2.68%
84.1th percentile
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libexif | < libexif 0.6.21-9 (bookworm) | libexif 0.6.21-9 (bookworm) |
| android | — | — | |
| libexif_project | libexif | < 0.6.22 | 0.6.22 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-9 | 0.6.21-9 |
| libexif_project | libexif | >= 0 < 0.6.21-2ubuntu0.5 | 0.6.21-2ubuntu0.5 |
| libexif_project | libexif | >= 0 < 0.6.21-4ubuntu0.5 | 0.6.21-4ubuntu0.5 |
| libexif_project | libexif | >= 0 < 0.6.21-6ubuntu0.3 | 0.6.21-6ubuntu0.3 |
| libexif_project | libexif | >= 0 < 0.6.21-1ubuntu1+esm5 | 0.6.21-1ubuntu1+esm5 |
| opensuse | leap | — | — |
| platform | external_libexif | >= 10:0 < 10:2022-02-01 | 10:2022-02-01 |
| platform | external_libexif | >= 11:0 < 11:2022-02-01 | 11:2022-02-01 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pxw-3px9-5fg9: An issue was discovered in libexif before 0
ghsa_unreviewed·2022-05-24·CVSS 5.0
CVE-2020-13112 [MEDIUM] CWE-125 GHSA-4pxw-3px9-5fg9: An issue was discovered in libexif before 0
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
OSV
CVE-2020-13112: In exif_entry_get_value of exif-entry
osv·2022-02-01
CVE-2020-13112 CVE-2020-13112: In exif_entry_get_value of exif-entry
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
libexif vulnerabilities
osv·2020-06-16·CVSS 5.0
CVE-2020-0093 [MEDIUM] libexif vulnerabilities
libexif vulnerabilities
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2020-0093, CVE-2020-0182)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a remote denial of service.
(CVE-2020-0198)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information or
cause a crash. (CVE-2020-13112)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2020-13113)
It was discovered libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a d
OSV
CVE-2020-13112: An issue was discovered in libexif before 0
osv·2020-05-21·CVSS 5.0
CVE-2020-13112 [MEDIUM] CVE-2020-13112: An issue was discovered in libexif before 0
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Android
CVE-2020-13112: Android Security Bulletin 2022-02-01
CVE: CVE-2020-13112
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11
References: A-194342672*
vendor_android·2022-02-01·CVSS 9.1
CVE-2020-13112 [CRITICAL] CVE-2020-13112: Android Security Bulletin 2022-02-01
CVE: CVE-2020-13112
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11
References: A-194342672*
Android Security Bulletin 2022-02-01
CVE: CVE-2020-13112
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11
References: A-194342672*
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2020-06-16·CVSS 5.0
CVE-2020-0093 [MEDIUM] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: Several security issues were fixed in libexif.
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2020-0093, CVE-2020-0182)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a remote denial of service.
(CVE-2020-0198)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information or
cause a crash. (CVE-2020-13112)
It was discovered that libexif incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2020-13113)
It was discovered libexif incorrectly handled certai
Red Hat
libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
vendor_redhat·2020-05-16·CVSS 5.0
CVE-2020-13112 [MEDIUM] CWE-122 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
A heap-buffer out-of-bounds read flaw was found in libexif's MakerNote tag parser. This flaw allows an unauthenticated attacker or authenticated attacker with low privileges to exploit the flaw remotely in an application that uses libexif to process EXIF data from media files if the file upload is allowed. An attacker could create a specially crafted image file that, when processed by libexif, would cause the application to crash or, potentially expose data from the application's memory. This atta
Debian
CVE-2020-13112: libexif - An issue was discovered in libexif before 0.6.22. Several buffer over-reads in E...
vendor_debian·2020·CVSS 5.0
CVE-2020-13112 [MEDIUM] CVE-2020-13112: libexif - An issue was discovered in libexif before 0.6.22. Several buffer over-reads in E...
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Scope: local
bookworm: resolved (fixed in 0.6.21-9)
bullseye: resolved (fixed in 0.6.21-9)
forky: resolved (fixed in 0.6.21-9)
sid: resolved (fixed in 0.6.21-9)
trixie: resolved (fixed in 0.6.21-9)
No detection rules found.
No public exploits indexed.
Qualys
A Deep Dive into VMDR 2.0 with Qualys TruRisk™
blogs_qualys·2022-08-08·CVSS 9.1
[CRITICAL] A Deep Dive into VMDR 2.0 with Qualys TruRisk™
## Table of Contents
Qualys TruRiskTM Weighs Multiple Risk Factors
About Qualys Detection Score (QDS)
Powered by a Comprehensive Exploit & Threat Intelligence Database
About TruRisk Score
TruRisk Score Formula
How Qualys TruRisk Visualizes Risk for an Organization
How to Prioritize Remediation using Qualys TruRisk scores
Qualys VMDR Reporting Now Includes TruRisk
Qualys TruRisk API Support
Qualys TruRisk Frequently Asset Questions (FAQs)
Whats Next?
The old way of ranking vulnerabilities doesn’t work anymore. Instead, enterprise security teams need to rate the true risks to their business. In this blog, we examine each of the risk scores delivered by Qualys TruRisk, the criteria used to compute them, and how they can be used to prioritize remediation.
Cybersecurity and IT team
Qualys
A Deep Dive into VMDR 2.0 with Qualys TruRisk™ | Qualys
blogs_qualys·2022-08-08·CVSS 9.1
[CRITICAL] A Deep Dive into VMDR 2.0 with Qualys TruRisk™ | Qualys
#### Table of Contents
- Qualys TruRiskTM Weighs Multiple Risk Factors
- About Qualys Detection Score (QDS)
- Powered by a Comprehensive Exploit & Threat Intelligence Database
- About TruRisk Score
- TruRisk Score Formula
- How Qualys TruRisk Visualizes Risk for an Organization
- How to Prioritize Remediation using Qualys TruRisk scores
- Qualys VMDR Reporting Now Includes TruRisk
- Qualys TruRisk API Support
- Qualys TruRisk Frequently Asset Questions (FAQs)
- Whats Next?
The old way of ranking vulnerabilities doesn’t work anymore. Instead, enterprise security teams need to rate the true risks to their business. In this blog, we examine each of the risk scores delivered by Qualys TruRisk, the criteria used to compute them, and how they can be used to prioritize remediation.
Cybersecuri
Bugzilla
CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
bugzilla·2020-05-26·CVSS 5.0
CVE-2020-13112 [MEDIUM] CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
Reference and upstream commit:
https://github.com/libexif/libexif/commit/435e21f05001fb03f9f186fa7cbc69454afd00d1
Discussion:
Created libexif tracking bugs for this issue:
Affects: fedora-all [bug 1840345]
---
====Technical Summary====
The libexif library parses an EXIF tag called a MakerNote. According to the EXIF standard[1], a MakerNote tag can hold manufacturer-specific data from camera manufacturers such as Nikon, Olympus, Canon, Panasonic, etc... The vulnerable component
Bugzilla
CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS [fedora-all]
bugzilla·2020-05-26·CVSS 9.1
CVE-2020-13112 [CRITICAL] CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS [fedora-all]
CVE-2020-13112 libexif: several buffer over-reads in EXIF MakerNote handling can lead to information disclosure and DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.htmlhttps://github.com/libexif/libexif/commit/435e21f05001fb03f9f186fa7cbc69454afd00d1https://lists.debian.org/debian-lts-announce/2020/05/msg00025.htmlhttps://security.gentoo.org/glsa/202007-05https://usn.ubuntu.com/4396-1/http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.htmlhttps://github.com/libexif/libexif/commit/435e21f05001fb03f9f186fa7cbc69454afd00d1https://lists.debian.org/debian-lts-announce/2020/05/msg00025.htmlhttps://security.gentoo.org/glsa/202007-05https://usn.ubuntu.com/4396-1/
2020-05-21
Published