An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html | Mailing List Third Party Advisory |
https://github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9bab | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/05/msg00025.html | Mailing List Third Party Advisory |
https://security.gentoo.org/glsa/202007-05 | Third Party Advisory |
https://usn.ubuntu.com/4396-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2020-05-21 16:15
Updated : 2022-04-27 14:45
NVD link : CVE-2020-13114
Mitre link : CVE-2020-13114
CVE.ORG link : CVE-2020-13114
JSON object : View
Products Affected
canonical
- ubuntu_linux
libexif_project
- libexif
opensuse
- leap
CWE
CWE-770
Allocation of Resources Without Limits or Throttling