PT-2020-6987 · Google+6 · Android+6

Published

2020-03-02

·

Updated

2024-06-15

·

CVE-2020-0093

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 10
Description The issue is related to a possible out of bounds read in the exif data save data entry function of exif-data.c due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions 8.0 through 10, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2019
ALT-PU-2020-2723
BDU:2024-07612
CESA-2020_4040
CESA-2020_4766
CVE-2020-0093
DLA-2214-1
DLA-2222-1
MGASA-2020-0238
OESA-2022-2006
OESA-2022-2008
OPENSUSE-SU-2020:0793-1
OPENSUSE-SU-2020_0793-1
OPENSUSE-SU-2024:10939-1
RHSA-2020:4040
RHSA-2020:4766
RHSA-2020_4040
RHSA-2020_4766
SUSE-SU-2020:1534-1
SUSE-SU-2020:1553-1
SUSE-SU-2020:1553-2
SUSE-SU-2020_1534-1
SUSE-SU-2020_1553-1
SUSE-SU-2020_1553-2
USN-4396-1

Affected Products

Alt Linux
Android
Centos
Linuxmint
Red Hat
Suse
Ubuntu