OESA-2021-1286
Dashboard / Vulnerabilities / OESA-2021-1286
OESA-2021-1286
Summary: libexif security update
Details: Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags. Security Fix(es): An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.(CVE-2020-13113) An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.(CVE-2020-13114)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1286, https://nvd.nist.gov/vuln/detail/CVE-2020-13113, https://nvd.nist.gov/vuln/detail/CVE-2020-13114
Affected packages
Package
Name: libexif
Purl: pkg:rpm/openEuler/libexif&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
