{"id":"MGASA-2020-0426","summary":"Updated libexif packages fix a security vulnerability","details":"In exif_entry_get_value of exif-entry.c, there is a possible out of bounds \nwrite due to an integer overflow. This could lead to remote code execution if\na third party app used this library to process remote image data with no\nadditional execution privileges needed. User interaction is not needed for\nexploitation. (CVE-2020-0452)\n","modified":"2026-04-16T04:43:28.376010539Z","published":"2020-11-15T15:45:05Z","upstream":["CVE-2020-0452"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0426.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27592"},{"type":"WEB","url":"https://www.debian.org/security/2020/dsa-4786"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4624-1"}],"affected":[{"package":{"name":"libexif","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/libexif?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.22-1.2.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0426.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}