libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://sourceforge.net/p/libexif/bugs/130/ | third party advisory exploit |
https://usn.ubuntu.com/4277-1/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2020/05/msg00016.html | mailing list |
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html | vendor advisory |