CVE-2020-13112

Public on 2020-05-21
Modified on 2020-07-15
Description

A heap-buffer out-of-bounds read flaw was found in libexif's MakerNote tag parser. This flaw allows an unauthenticated attacker or authenticated attacker with low privileges to exploit the flaw remotely in an application that uses libexif to process EXIF data from media files if the file upload is allowed. An attacker could create a specially crafted image file that, when processed by libexif, would cause the application to crash or, potentially expose data from the application's memory. This attack leads to a denial of service or a memory information leak that could assist in further exploitation.

Severity
Medium
See what this means
CVSS v3 Base Score
9.1
See breakdown

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 1 libexif 2020-07-14 01:51 ALAS-2020-1393
Amazon Linux 2 - Core libexif 2020-06-26 22:52 ALAS2-2020-1443

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
NVD CVSSv3 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
NVD CVSSv2 6.4 AV:N/AC:L/Au:N/C:P/I:N/A:P