In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731 References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ELDZR6USD5PR34MRK2ZISLCYJ465FNKN/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVBD5JRUQPN4LQHTAAJHA3MR5M7YTAC7/ https://security.gentoo.org/glsa/202011-19
Created libexif tracking bugs for this issue: Affects: fedora-all [bug 1902005]
Upstream commit: https://github.com/libexif/libexif/commit/9266d14b5ca4e29b970fa03272318e5f99386e06#diff-7ee66c4f1536ac84dc5bbff1b8312e2eef24b974b3e48a5c5c2bcfdf2eb8f3ce
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:5396 https://access.redhat.com/errata/RHSA-2020:5396
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2020:5395 https://access.redhat.com/errata/RHSA-2020:5395
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:5393 https://access.redhat.com/errata/RHSA-2020:5393
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2020:5394 https://access.redhat.com/errata/RHSA-2020:5394
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-0452
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:5402 https://access.redhat.com/errata/RHSA-2020:5402