CVE-2020-0452 (High) detected in libexifandroid-10.0.0_r6
Opened this issue · 0 comments
CVE-2020-0452 - High Severity Vulnerability
Vulnerable Library - libexifandroid-10.0.0_r6
Library home page: https://android.googlesource.com/platform/external/libexif
Found in HEAD commit: 2a65e5ce8119532b3e55541c20b0c577311276da
Found in base branch: master
Vulnerability Details
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731
Publish Date: 2020-11-10
URL: CVE-2020-0452
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: https://android.googlesource.com/platform/external/libexif/+/refs/tags/android-11.0.0_r12
Release Date: 2020-11-10
Fix Resolution: android-11.0.0_r12
Step up your Open Source Security Game with WhiteSource here