CVE-2019-9278
Summary
| CVE | CVE-2019-9278 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-27 19:15:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774 |
Risk And Classification
Problem Types: CWE-787 | CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Android | 10.0 | All | All | All | |
| Operating System | Android | 10.0 | All | All | All | |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 32 Update: libexif-0.6.22-1.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| fix CVE-2019-9278 · libexif/libexif@75aa732 · GitHub | CONFIRM | github.com | |
| [security-announce] openSUSE-SU-2020:0793-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-4618-1 libexif | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 31 Update: libexif-0.6.22-1.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| oss-security - Re: Security fixes from Android 10 release which are relevant outside the Android ecosystem? | MLIST | www.openwall.com | |
| Bugtraq: [SECURITY] [DSA 4618-1] libexif security update | BUGTRAQ | seclists.org | |
| libexif: Multiple vulnerabilities (GLSA 202007-05) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 31 Update: libexif-0.6.22-1.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Relevant commit for CVE-2019-9278 · Issue #26 · libexif/libexif · GitHub | CONFIRM | github.com | |
| oss-security - Re: Security fixes from Android 10 release which are relevant outside the Android ecosystem? | MLIST | www.openwall.com | |
| [SECURITY] Fedora 32 Update: libexif-0.6.22-1.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Android 10 Security Release Notes | Android Open Source Project | MISC | source.android.com | Vendor Advisory |
| oss-security - Security fixes from Android 10 release which are relevant outside the Android ecosystem? | MLIST | www.openwall.com | |
| [security-announce] openSUSE-SU-2020:0264-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [SECURITY] [DLA 2100-1] libexif security update | MLIST | lists.debian.org | |
| USN-4277-1: libexif vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377246 Alibaba Cloud Linux Security Update for libexif (ALINUX2-SA-2020:0157)
- 500291 Alpine Linux Security Update for libexif
- 690461 Free Berkeley Software Distribution (FreeBSD) Security Update for libexif (cff0b2e2-0716-11eb-9e5d-08002728f74c)