An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html | Mailing List Third Party Advisory |
https://github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9bab | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/05/msg00025.html | Mailing List Third Party Advisory |
https://security.gentoo.org/glsa/202007-05 | Third Party Advisory |
https://usn.ubuntu.com/4396-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
27 Apr 2022, 14:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
|
CWE | CWE-770 | |
References | (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html - Mailing List, Third Party Advisory | |
References | (UBUNTU) https://usn.ubuntu.com/4396-1/ - Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2020/05/msg00025.html - Mailing List, Third Party Advisory | |
References | (GENTOO) https://security.gentoo.org/glsa/202007-05 - Third Party Advisory |
Information
Published : 2020-05-21 16:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-13114
Mitre link : CVE-2020-13114
CVE.ORG link : CVE-2020-13114
JSON object : View
Products Affected
libexif_project
- libexif
canonical
- ubuntu_linux
opensuse
- leap
CWE
CWE-770
Allocation of Resources Without Limits or Throttling