CVE-2020-13114

Name
CVE-2020-13114
Description
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9bab
Third Party Advisory https://lists.debian.org/debian-lts-announce/2020/05/msg00025.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html
UBUNTU https://usn.ubuntu.com/4396-1/
GENTOO https://security.gentoo.org/glsa/202007-05

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* libexif >= None < 0.6.22

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libexif 3.13-community 0.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libexif 3.12-main 0.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libexif 3.11-main 0.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libexif 3.10-main 0.6.22-r0 Natanael Copa <ncopa@alpinelinux.org> fixed