7.5
CVSSv3

CVE-2020-0198

Published: 11/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

It exists that libexif incorrectly handled certain inputs. An attacker could possibly use this issue to expose sensitive information. (CVE-2020-0093, CVE-2020-0182)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 10.0

debian debian linux 8.0

canonical ubuntu linux 18.04

canonical ubuntu linux 14.04

canonical ubuntu linux 19.10

fedoraproject fedora 32

canonical ubuntu linux 20.04

fedoraproject fedora 33

canonical ubuntu linux 16.04

canonical ubuntu linux 12.04

libexif project libexif

Vendor Advisories

Synopsis Moderate: libexif security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for libexif is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Sy ...
Several security issues were fixed in libexif ...
Debian Bug report logs - #962345 CVE-2020-0198 Package: src:libexif; Maintainer for src:libexif is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 6 Jun 2020 14:09:02 UTC Severity: important Tags: security Reply or subscr ...
Debian Bug report logs - #962346 CVE-2020-0181 Package: src:libexif; Maintainer for src:libexif is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 6 Jun 2020 14:15:01 UTC Severity: important Tags: security Reply or subscr ...
In libexif before version 0623, in exif_data_load_data_content of exif-datac, there is a possible UBSAN abort due to an integer overflow This could lead to remote denial of service with no additional execution privileges needed User interaction is needed for exploitation ...