CVE Vulnerabilities

CVE-2020-13113

Use of Uninitialized Resource

Published: May 21, 2020 | Modified: Nov 21, 2024
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
8.2 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
LibexifLibexif_project*0.6.22 (excluding)
Red Hat Enterprise Linux 7RedHatlibexif-0:0.6.22-1.el7*
Red Hat Enterprise Linux 8RedHatlibexif-0:0.6.22-4.el8*
LibexifUbuntubionic*
LibexifUbuntueoan*
LibexifUbuntuesm-infra-legacy/trusty*
LibexifUbuntuesm-infra/bionic*
LibexifUbuntuesm-infra/focal*
LibexifUbuntuesm-infra/xenial*
LibexifUbuntufocal*
LibexifUbuntutrusty*
LibexifUbuntutrusty/esm*
LibexifUbuntuxenial*

Potential Mitigations

References