ISOMAN

CVE

CVE-2019-9278

In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774

Severity
HIGH
CVSS
8.8
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00000.html
  2. http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html
  3. http://www.openwall.com/lists/oss-security/2019/10/25/17
  4. http://www.openwall.com/lists/oss-security/2019/10/27/1
  5. http://www.openwall.com/lists/oss-security/2019/11/07/1
  6. https://github.com/libexif/libexif/commit/75aa73267fdb1e0ebfbc00369e7312bac43d0566
  7. https://github.com/libexif/libexif/issues/26
  8. https://lists.debian.org/debian-lts-announce/2020/02/msg00007.html
  9. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO2VTHD7OLPJDCJBHKUQTBAHZOBBCF6X/
  10. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VA5BPQLOFXIZOOJHBYDU635Z5KLUMTDD/
  11. https://seclists.org/bugtraq/2020/Feb/9
  12. https://security.gentoo.org/glsa/202007-05
  13. https://source.android.com/security/bulletin/android-10
  14. https://usn.ubuntu.com/4277-1/
  15. https://www.debian.org/security/2020/dsa-4618
  16. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00000.html
  17. http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html
  18. http://www.openwall.com/lists/oss-security/2019/10/25/17
  19. http://www.openwall.com/lists/oss-security/2019/10/27/1
  20. http://www.openwall.com/lists/oss-security/2019/11/07/1