High severity7.5NVD Advisory· Published May 21, 2020· Updated Jun 17, 2026
CVE-2020-13114
CVE-2020-13114
Description
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
35cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*range: <0.6.22
- (no CPE)range: <0.6.22
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*+ 5 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- libexif/libexifdescription
- osv-coords25 versionspkg:rpm/opensuse/libexif&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/libexif&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libexif&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/libexif&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/libexif&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/libexif&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/libexif&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
< 0.6.22-lp151.4.6.1+ 24 more
- (no CPE)range: < 0.6.22-lp151.4.6.1
- (no CPE)range: < 0.6.23-1.2
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-5.6.1
- (no CPE)range: < 0.6.22-5.6.1
- (no CPE)range: < 0.6.22-5.6.1
- (no CPE)range: < 0.6.22-5.6.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
- (no CPE)range: < 0.6.22-8.9.1
Patches
Vulnerability mechanics
References
5- github.com/libexif/libexif/commit/e6a38a1a23ba94d139b1fa2cd4519fdcfe3c9babnvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/05/msg00025.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202007-05nvdThird Party Advisory
- usn.ubuntu.com/4396-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.