Alerts This Week
Warning Icon 1 1,394
Alerts This Week
Warning Icon 1 1,394

Ubuntu 20.04 LTS: USN-4358-1 Moderate: libexif Denial Of Service

ubuntu
Calendar Grey May 13, 2020
Dist Ubuntu Esm H88
Multiple vulnerabilities in libexif addressed through Ubuntu security updates to avert potential service interruptions and application failures.
Several security issues were fixed in libexif.

Summary

Several security issues were fixed in libexif.

Software Description:

- libexif: library to parse EXIF files

Details:

It was discovered that libexif incorrectly handled certain tags.

An attacker could possibly use this issue to cause a denial of service.

(CVE-2018-20030)

It was discovered that libexif incorrectly handled certain inputs.

An attacker could possibly use this issue to cause a crash.

(CVE-2020-12767)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libexif12                       0.6.21-6ubuntu0.1

Ubuntu 19.10:
  libexif12                       0.6.21-5.1ubuntu0.2

Ubuntu 18.04 LTS:
  libexif12                       0.6.21-4ubuntu0.2

Ubuntu 16.04 LTS:
  libexif12                       0.6.21-2ubuntu0.2

Ubuntu 14.04 ESM:
  libexif12                       0.6.21-1ubuntu1+esm2

Ubuntu 12.04 ESM:
  libexif12                       0.6.20-2ubuntu0.3

After a standard system update you need to restart your session to
effect the necessary changes.

References

https://ubuntu.com/security/notices/USN-4358-1

CVE-2018-20030, CVE-2020-12767

Severity
important
Lowest
Low
Medium
High
Critical

May 13, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here