An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/libexif/+/c9da78d8d9f302c767b366ef256e24fa32f8784f",
"https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232"
],
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-45cb83fc",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/olympus/exif-mnote-data-olympus.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"171665474353090061899021564791197257152",
"116301063513059510679027604740839939787",
"33983948157538593294138539723360334410",
"231840623465655071498280023479608178034"
]
},
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-500e6a39",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_pentax_load",
"file": "libexif/pentax/exif-mnote-data-pentax.c"
},
"digest": {
"length": 3510.0,
"function_hash": "183404549225358201605541302295976617143"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-52cf7f82",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_canon_load",
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"digest": {
"length": 2636.0,
"function_hash": "230472758768611256226825674298003938134"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-5d4bce62",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/fuji/exif-mnote-data-fuji.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"182556739721751607620424315492830018068",
"63090266439464873986942635232246469126",
"133352749772712821961584651055235107129",
"59814921405938895402439206079570764350"
]
},
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-66798d65",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_fuji_load",
"file": "libexif/fuji/exif-mnote-data-fuji.c"
},
"digest": {
"length": 2820.0,
"function_hash": "113168632477656210553710536030160313989"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-adb7db80",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_olympus_load",
"file": "libexif/olympus/exif-mnote-data-olympus.c"
},
"digest": {
"length": 6441.0,
"function_hash": "189747278139490779873991802493815478765"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-dd189b4f",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/pentax/exif-mnote-data-pentax.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"182556739721751607620424315492830018068",
"63090266439464873986942635232246469126",
"133352749772712821961584651055235107129",
"87180012295696138925344357238405859904"
]
},
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-e339df47",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"182556739721751607620424315492830018068",
"63090266439464873986942635232246469126",
"225602874433340598213515522161546468010",
"215464518781960057437098919856189329355"
]
},
"signature_type": "Line"
}
],
"severity": "High",
"spl": "2022-02-01"
}
{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/external/libexif/+/c9da78d8d9f302c767b366ef256e24fa32f8784f",
"https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232"
],
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-130a0623",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"182556739721751607620424315492830018068",
"63090266439464873986942635232246469126",
"225602874433340598213515522161546468010",
"215464518781960057437098919856189329355"
]
},
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-20c7c86e",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_pentax_load",
"file": "libexif/pentax/exif-mnote-data-pentax.c"
},
"digest": {
"length": 3510.0,
"function_hash": "183404549225358201605541302295976617143"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-3144475c",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_fuji_load",
"file": "libexif/fuji/exif-mnote-data-fuji.c"
},
"digest": {
"length": 2820.0,
"function_hash": "113168632477656210553710536030160313989"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-6aaef996",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/fuji/exif-mnote-data-fuji.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"182556739721751607620424315492830018068",
"63090266439464873986942635232246469126",
"133352749772712821961584651055235107129",
"59814921405938895402439206079570764350"
]
},
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-901b89c8",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/olympus/exif-mnote-data-olympus.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"171665474353090061899021564791197257152",
"116301063513059510679027604740839939787",
"33983948157538593294138539723360334410",
"231840623465655071498280023479608178034"
]
},
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-a972d32c",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_canon_load",
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"digest": {
"length": 2636.0,
"function_hash": "230472758768611256226825674298003938134"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-ad14afa8",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_olympus_load",
"file": "libexif/olympus/exif-mnote-data-olympus.c"
},
"digest": {
"length": 6441.0,
"function_hash": "189747278139490779873991802493815478765"
},
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232",
"id": "ASB-A-196085005-c70dca5d",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libexif/pentax/exif-mnote-data-pentax.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"182556739721751607620424315492830018068",
"63090266439464873986942635232246469126",
"133352749772712821961584651055235107129",
"87180012295696138925344357238405859904"
]
},
"signature_type": "Line"
}
],
"severity": "High",
"spl": "2022-02-01"
}