An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "171665474353090061899021564791197257152", "116301063513059510679027604740839939787", "33983948157538593294138539723360334410", "231840623465655071498280023479608178034" ] }, "id": "ASB-A-196085005-45cb83fc", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/olympus/exif-mnote-data-olympus.c" }, "signature_type": "Line" }, { "digest": { "length": 3510.0, "function_hash": "183404549225358201605541302295976617143" }, "id": "ASB-A-196085005-500e6a39", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/pentax/exif-mnote-data-pentax.c", "function": "exif_mnote_data_pentax_load" }, "signature_type": "Function" }, { "digest": { "length": 2636.0, "function_hash": "230472758768611256226825674298003938134" }, "id": "ASB-A-196085005-52cf7f82", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/canon/exif-mnote-data-canon.c", "function": "exif_mnote_data_canon_load" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "182556739721751607620424315492830018068", "63090266439464873986942635232246469126", "133352749772712821961584651055235107129", "59814921405938895402439206079570764350" ] }, "id": "ASB-A-196085005-5d4bce62", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/fuji/exif-mnote-data-fuji.c" }, "signature_type": "Line" }, { "digest": { "length": 2820.0, "function_hash": "113168632477656210553710536030160313989" }, "id": "ASB-A-196085005-66798d65", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/fuji/exif-mnote-data-fuji.c", "function": "exif_mnote_data_fuji_load" }, "signature_type": "Function" }, { "digest": { "length": 6441.0, "function_hash": "189747278139490779873991802493815478765" }, "id": "ASB-A-196085005-adb7db80", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/olympus/exif-mnote-data-olympus.c", "function": "exif_mnote_data_olympus_load" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "182556739721751607620424315492830018068", "63090266439464873986942635232246469126", "133352749772712821961584651055235107129", "87180012295696138925344357238405859904" ] }, "id": "ASB-A-196085005-dd189b4f", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/pentax/exif-mnote-data-pentax.c" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "182556739721751607620424315492830018068", "63090266439464873986942635232246469126", "225602874433340598213515522161546468010", "215464518781960057437098919856189329355" ] }, "id": "ASB-A-196085005-e339df47", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/canon/exif-mnote-data-canon.c" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/libexif/+/c9da78d8d9f302c767b366ef256e24fa32f8784f", "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232" ], "spl": "2022-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "182556739721751607620424315492830018068", "63090266439464873986942635232246469126", "225602874433340598213515522161546468010", "215464518781960057437098919856189329355" ] }, "id": "ASB-A-196085005-130a0623", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/canon/exif-mnote-data-canon.c" }, "signature_type": "Line" }, { "digest": { "length": 3510.0, "function_hash": "183404549225358201605541302295976617143" }, "id": "ASB-A-196085005-20c7c86e", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/pentax/exif-mnote-data-pentax.c", "function": "exif_mnote_data_pentax_load" }, "signature_type": "Function" }, { "digest": { "length": 2820.0, "function_hash": "113168632477656210553710536030160313989" }, "id": "ASB-A-196085005-3144475c", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/fuji/exif-mnote-data-fuji.c", "function": "exif_mnote_data_fuji_load" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "182556739721751607620424315492830018068", "63090266439464873986942635232246469126", "133352749772712821961584651055235107129", "59814921405938895402439206079570764350" ] }, "id": "ASB-A-196085005-6aaef996", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/fuji/exif-mnote-data-fuji.c" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "171665474353090061899021564791197257152", "116301063513059510679027604740839939787", "33983948157538593294138539723360334410", "231840623465655071498280023479608178034" ] }, "id": "ASB-A-196085005-901b89c8", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/olympus/exif-mnote-data-olympus.c" }, "signature_type": "Line" }, { "digest": { "length": 2636.0, "function_hash": "230472758768611256226825674298003938134" }, "id": "ASB-A-196085005-a972d32c", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/canon/exif-mnote-data-canon.c", "function": "exif_mnote_data_canon_load" }, "signature_type": "Function" }, { "digest": { "length": 6441.0, "function_hash": "189747278139490779873991802493815478765" }, "id": "ASB-A-196085005-ad14afa8", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/olympus/exif-mnote-data-olympus.c", "function": "exif_mnote_data_olympus_load" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "182556739721751607620424315492830018068", "63090266439464873986942635232246469126", "133352749772712821961584651055235107129", "87180012295696138925344357238405859904" ] }, "id": "ASB-A-196085005-c70dca5d", "source": "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232", "deprecated": false, "signature_version": "v1", "target": { "file": "libexif/pentax/exif-mnote-data-pentax.c" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/libexif/+/c9da78d8d9f302c767b366ef256e24fa32f8784f", "https://android.googlesource.com/platform/external/libexif/+/4ceb535b530fd8d0504c9df65c99045a71e12232" ], "spl": "2022-02-01", "severity": "High", "types": [ "EoP" ] }