Vulnerability Name:

CVE-2020-0181 (CCN-183525)

Assigned:2019-10-17
Published:2020-06-01
Updated:2022-10-14
Summary:In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145075076
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
8.2 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
7.1 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-190
CWE-787
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Google Web site
Android

Source: MITRE
Type: CNA
CVE-2020-0181

Source: XF
Type: UNKNOWN
android-cve20200181-dos(183525)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-0aa0fc1b0c

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-e99ef3282f

Source: GENTOO
Type: Third Party Advisory
GLSA-202011-19

Source: CCN
Type: Android Open Source Project
Pixel Update Bulletin—June 2020

Source: MISC
Type: Patch, Vendor Advisory
https://source.android.com/security/bulletin/pixel/2020-06-01

Vulnerable Configuration:Configuration 1:
  • cpe:/o:google:android:10.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OR cpe:/a:libexif_project:libexif:*:*:*:*:*:*:*:* (Version < 0.6.22_p20201105)

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:google:android:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7929
    P
    libexif-devel-0.6.22-150000.5.9.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3309
    P
    openslp-2.0.0-18.20.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3728
    P
    opensc-0.13.0-3.3.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94939
    P
    libexif-devel-0.6.22-150000.5.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:126857
    P
    Security update for libexif (Important)
    2022-04-12
    oval:org.opensuse.security:def:127254
    P
    Security update for libexif (Important)
    2022-04-12
    oval:org.opensuse.security:def:5217
    P
    Security update for libexif (Important)
    2022-04-12
    oval:org.opensuse.security:def:125691
    P
    Security update for libexif (Important)
    2022-04-12
    oval:org.opensuse.security:def:6007
    P
    Security update for libexif (Important)
    2022-04-12
    oval:org.opensuse.security:def:119170
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:118673
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:1504
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:119360
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:95358
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:101750
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:118863
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:119545
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:102084
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:119052
    P
    Security update for libexif (Important)
    2022-04-11
    oval:org.opensuse.security:def:1059
    P
    Security update for libexif (Important)
    2022-04-11
    oval:com.redhat.rhsa:def:20204766
    P
    RHSA-2020:4766: libexif security, bug fix, and enhancement update (Moderate)
    2020-11-04
    BACK
    google android 10.0
    fedoraproject fedora 32
    fedoraproject fedora 33
    libexif_project libexif *
    google android *