An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
[
{
"id": "CVE-2020-13114-2913e4b7",
"target": {
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"digest": {
"line_hashes": [
"183661055639346139562865211106879471593",
"102180397425500091626994875092804653997",
"306305871760784389225367867808059433294",
"207782849275302793484543269879757525988",
"299962798900018550672650127921689935553",
"137645713422839848331569839100485136820",
"65281336464964645892986813792569762885",
"136226467884528459531799921885828871006",
"211654736396785424026722509724167862913",
"164442592703984623745953044333516937576"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9bab",
"signature_type": "Line"
},
{
"id": "CVE-2020-13114-2b6322a1",
"target": {
"function": "exif_mnote_data_canon_load",
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"digest": {
"length": 2731.0,
"function_hash": "275829830554807676188843136336972106671"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9bab",
"signature_type": "Function"
}
]