CVE-2020-1577
published 2020-08-17CVE-2020-1577: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
7.09%
93.5th percentile
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-25qw-9qm7-q8v7: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu
ghsa_unreviewed·2022-05-24
CVE-2020-1577 [MEDIUM] CWE-200 GHSA-25qw-9qm7-q8v7: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosu
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.
Microsoft
DirectWrite Information Disclosure Vulnerability
vendor_msrc·2020-08-11·CVSS 5.5
CVE-2020-1577 [HIGH] DirectWrite Information Disclosure Vulnerability
DirectWrite Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage.
The security update addresses the vulnerability by correcting how DirectWrite handles objects in memory.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the contents of Kernel m
No detection rules found.
No public exploits indexed.
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
Exploits & Vulnerabilities
# Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro
2020/08/11
Read time: ( words)
Save to Folio
Update on 08/19/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used f
Bugzilla
CVE-2019-13113 exiv2: invalid data location in CRW image file causing denial of service
bugzilla·2019-07-10·CVSS 6.5
CVE-2019-13113 [MEDIUM] CVE-2019-13113 exiv2: invalid data location in CRW image file causing denial of service
CVE-2019-13113 exiv2: invalid data location in CRW image file causing denial of service
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
Reference:
https://github.com/Exiv2/exiv2/issues/841
https://github.com/Exiv2/exiv2/pull/842
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1728493]
---
Upstream patch:
https://github.com/Exiv2/exiv2/commit/6212806b7637be683a56c769a8d905153996d933 [master branch]
https://github.com/Exiv2/exiv2/commit/7798ae25574425271305fffe85de77bec8df03f1 [0.27-maintenance branch]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2
Bugzilla
CVE-2019-9143 exiv2: infinite recursion in Exiv2::Image::printTiffStructure in file image.cpp resulting in denial of service
bugzilla·2019-03-01·CVSS 8.8
CVE-2019-9143 [HIGH] CVE-2019-9143 exiv2: infinite recursion in Exiv2::Image::printTiffStructure in file image.cpp resulting in denial of service
CVE-2019-9143 exiv2: infinite recursion in Exiv2::Image::printTiffStructure in file image.cpp resulting in denial of service
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Reference:
https://github.com/Exiv2/exiv2/issues/711
https://research.loginsoft.com/vulnerability/uncontrolled-recursion-loop-in-exiv2imageprinttiffstructure-exiv2-0-27/
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1684382]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redh
Bugzilla
CVE-2018-17229 exiv2: heap-based buffer overflow in Exiv2::d2Data in types.cpp
bugzilla·2018-09-24·CVSS 6.5
CVE-2018-17229 [MEDIUM] CVE-2018-17229 exiv2: heap-based buffer overflow in Exiv2::d2Data in types.cpp
CVE-2018-17229 exiv2: heap-based buffer overflow in Exiv2::d2Data in types.cpp
A flaw was found in Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
References:
https://github.com/Exiv2/exiv2/issues/453
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1632482]
---
Upstream patch:
https://github.com/Exiv2/exiv2/commit/afb98cbc6e288dc8ea75f3394a347fb9b37abc55
---
Statement:
This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include the vulnerable code.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redhat.com/er
Bugzilla
CVE-2018-17230 exiv2: heap-based buffer overflow in Exiv2::ul2Data in types.cpp
bugzilla·2018-09-24·CVSS 6.5
CVE-2018-17230 [MEDIUM] CVE-2018-17230 exiv2: heap-based buffer overflow in Exiv2::ul2Data in types.cpp
CVE-2018-17230 exiv2: heap-based buffer overflow in Exiv2::ul2Data in types.cpp
A flaw was found in Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
References:
https://github.com/Exiv2/exiv2/issues/455
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1632485]
---
Upstream patch:
https://github.com/Exiv2/exiv2/commit/afb98cbc6e288dc8ea75f3394a347fb9b37abc55
---
Statement:
This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include the vulnerable code.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redhat.com/
Bugzilla
CVE-2018-14338 exiv2: buffer overflow in samples/geotag.cpp
bugzilla·2018-07-27·CVSS 8.1
CVE-2018-14338 [HIGH] CVE-2018-14338 exiv2: buffer overflow in samples/geotag.cpp
CVE-2018-14338 exiv2: buffer overflow in samples/geotag.cpp
A flaw was found in Exiv2 0.26. The samples/geotag.cpp in the example code misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.
References:
https://github.com/Exiv2/exiv2/issues/382
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1609397]
---
We don't ship this. Additionally, this is should not be a problem for us, as we use glibc and realpath() should allocate the buffer there.
---
Statement:
This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6 and 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 h
Bugzilla
CVE-2018-9303 exiv2: assertion failure in BigTiffImage::readData in bigtiffimage.cpp
bugzilla·2018-04-12·CVSS 6.5
CVE-2018-9303 [MEDIUM] CVE-2018-9303 exiv2: assertion failure in BigTiffImage::readData in bigtiffimage.cpp
CVE-2018-9303 exiv2: assertion failure in BigTiffImage::readData in bigtiffimage.cpp
A flaw was found in Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort.
References:
https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1566727]
---
Statement:
This issue did not affect the versions of Exiv2 as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include support for BigTIFF images.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577
Bugzilla
CVE-2018-9304 exiv2: divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp
bugzilla·2018-04-12·CVSS 6.5
CVE-2018-9304 [MEDIUM] CVE-2018-9304 exiv2: divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp
CVE-2018-9304 exiv2: divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp
A flaw was found in Exiv2 0.26, a divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp could result in denial of service.
References:
https://github.com/Exiv2/exiv2/issues/262
https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1566727]
---
Statement:
This issue did not affect the versions of Exiv2 as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include support for BigTIFF images.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577
Bugzilla
CVE-2018-4868 exiv2: Excessive memory allocation in Exiv2::Jp2Image::readMetadata function in jp2image.cpp
bugzilla·2018-01-05·CVSS 5.5
CVE-2018-4868 [MEDIUM] CVE-2018-4868 exiv2: Excessive memory allocation in Exiv2::Jp2Image::readMetadata function in jp2image.cpp
CVE-2018-4868 exiv2: Excessive memory allocation in Exiv2::Jp2Image::readMetadata function in jp2image.cpp
The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file.
Upstream Issue:
https://github.com/Exiv2/exiv2/issues/202
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1531729]
---
Upstream patch:
https://github.com/Exiv2/exiv2/commit/9cddfa514d4fddf7a5f93be74dae2e93d9722204
---
A big allocation, caused by not enough checks, is present in Jp2Image::redMetadata() when the box type is Jp2Header and the subBox is ColorHeader.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577
Bugzilla
CVE-2017-18005 exiv2: null pointer dereference in the Exiv2::DataValue::toLong function in value.cpp
bugzilla·2018-01-04·CVSS 5.5
CVE-2017-18005 [MEDIUM] CVE-2017-18005 exiv2: null pointer dereference in the Exiv2::DataValue::toLong function in value.cpp
CVE-2017-18005 exiv2: null pointer dereference in the Exiv2::DataValue::toLong function in value.cpp
Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a malformed TIFF file. The vulnerability causes a segmentation fault.
[UPSTREAM BUG]
https://github.com/Exiv2/exiv2/issues/168
[UPSTREAM PATCH]
https://github.com/Exiv2/exiv2/pull/199
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2017-18005
2020-08-17
Published