An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
References
Link | Resource |
---|---|
https://github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9bab | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/05/msg00025.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html | Mailing List Third Party Advisory |
https://usn.ubuntu.com/4396-1/ | Third Party Advisory |
https://security.gentoo.org/glsa/202007-05 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2020-05-21 09:15
Updated : 2022-04-27 07:45
NVD link : CVE-2020-13114
Mitre link : CVE-2020-13114
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
canonical
- ubuntu_linux
libexif_project
- libexif
opensuse
- leap