Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags.
Security Fix(es):
In exifentryget_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731(CVE-2020-0452)
{ "severity": "Critical" }
{ "src": [ "libexif-0.6.21-26.oe1.src.rpm" ], "x86_64": [ "libexif-devel-0.6.21-26.oe1.x86_64.rpm", "libexif-0.6.21-26.oe1.x86_64.rpm", "libexif-debugsource-0.6.21-26.oe1.x86_64.rpm", "libexif-debuginfo-0.6.21-26.oe1.x86_64.rpm" ], "noarch": [ "libexif-help-0.6.21-26.oe1.noarch.rpm" ], "aarch64": [ "libexif-debuginfo-0.6.21-26.oe1.aarch64.rpm", "libexif-debugsource-0.6.21-26.oe1.aarch64.rpm", "libexif-devel-0.6.21-26.oe1.aarch64.rpm", "libexif-0.6.21-26.oe1.aarch64.rpm" ] }
{ "src": [ "libexif-0.6.21-26.oe2003sp4.src.rpm" ], "x86_64": [ "libexif-devel-0.6.21-26.oe2003sp4.x86_64.rpm", "libexif-debugsource-0.6.21-26.oe2003sp4.x86_64.rpm", "libexif-0.6.21-26.oe2003sp4.x86_64.rpm", "libexif-debuginfo-0.6.21-26.oe2003sp4.x86_64.rpm" ], "noarch": [ "libexif-help-0.6.21-26.oe2003sp4.noarch.rpm" ], "aarch64": [ "libexif-devel-0.6.21-26.oe2003sp4.aarch64.rpm", "libexif-0.6.21-26.oe2003sp4.aarch64.rpm", "libexif-debugsource-0.6.21-26.oe2003sp4.aarch64.rpm", "libexif-debuginfo-0.6.21-26.oe2003sp4.aarch64.rpm" ] }
{ "src": [ "libexif-0.6.22-5.oe2203.src.rpm", "libexif-0.6.22-5.oe2203sp1.src.rpm", "libexif-0.6.22-5.oe2203sp2.src.rpm", "libexif-0.6.22-5.oe2203sp3.src.rpm" ], "x86_64": [ "libexif-debugsource-0.6.22-5.oe2203.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203.x86_64.rpm", "libexif-0.6.22-5.oe2203.x86_64.rpm", "libexif-debuginfo-0.6.22-5.oe2203.x86_64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-0.6.22-5.oe2203sp3.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203sp3.x86_64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp3.x86_64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp3.x86_64.rpm" ], "noarch": [ "libexif-help-0.6.22-5.oe2203.noarch.rpm", "libexif-help-0.6.22-5.oe2203sp1.noarch.rpm", "libexif-help-0.6.22-5.oe2203sp2.noarch.rpm", "libexif-help-0.6.22-5.oe2203sp3.noarch.rpm" ], "aarch64": [ "libexif-devel-0.6.22-5.oe2203.aarch64.rpm", "libexif-0.6.22-5.oe2203.aarch64.rpm", "libexif-debugsource-0.6.22-5.oe2203.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203.aarch64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-devel-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-devel-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-0.6.22-5.oe2203sp3.aarch64.rpm", "libexif-devel-0.6.22-5.oe2203sp3.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp3.aarch64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp3.aarch64.rpm" ] }
{ "src": [ "libexif-0.6.22-5.oe2203sp1.src.rpm" ], "x86_64": [ "libexif-debuginfo-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp1.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203sp1.x86_64.rpm" ], "noarch": [ "libexif-help-0.6.22-5.oe2203sp1.noarch.rpm" ], "aarch64": [ "libexif-debugsource-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-devel-0.6.22-5.oe2203sp1.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp1.aarch64.rpm" ] }
{ "src": [ "libexif-0.6.22-5.oe2203sp2.src.rpm" ], "x86_64": [ "libexif-debugsource-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp2.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203sp2.x86_64.rpm" ], "noarch": [ "libexif-help-0.6.22-5.oe2203sp2.noarch.rpm" ], "aarch64": [ "libexif-devel-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp2.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp2.aarch64.rpm" ] }
{ "src": [ "libexif-0.6.22-5.oe2203sp3.src.rpm" ], "x86_64": [ "libexif-0.6.22-5.oe2203sp3.x86_64.rpm", "libexif-devel-0.6.22-5.oe2203sp3.x86_64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp3.x86_64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp3.x86_64.rpm" ], "noarch": [ "libexif-help-0.6.22-5.oe2203sp3.noarch.rpm" ], "aarch64": [ "libexif-0.6.22-5.oe2203sp3.aarch64.rpm", "libexif-devel-0.6.22-5.oe2203sp3.aarch64.rpm", "libexif-debuginfo-0.6.22-5.oe2203sp3.aarch64.rpm", "libexif-debugsource-0.6.22-5.oe2203sp3.aarch64.rpm" ] }