Lucene search

K
redhatcveRedhat.comRH:CVE-2020-13112
HistoryMay 26, 2020 - 7:15 p.m.

CVE-2020-13112

2020-05-2619:15:38
redhat.com
access.redhat.com
11

EPSS

0.002

Percentile

60.4%

A heap-buffer out-of-bounds read flaw was found in libexif’s MakerNote tag parser. This flaw allows an unauthenticated attacker or authenticated attacker with low privileges to exploit the flaw remotely in an application that uses libexif to process EXIF data from media files if the file upload is allowed. An attacker could create a specially crafted image file that, when processed by libexif, would cause the application to crash or, potentially expose data from the application’s memory. This attack leads to a denial of service or a memory information leak that could assist in further exploitation.