An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
{
"unresolved_ranges": [
{
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.04"
},
{
"last_affected": "14.04"
},
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "19.10"
},
{
"last_affected": "20.04"
}
]
},
{
"vendor_product": "debian:debian_linux",
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.0"
}
]
},
{
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15.1"
}
]
}
]
}{
"cpe": "cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.6.22"
}
]
}{
"cpe": "cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*",
"source": [
"CPE_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.6.22"
}
]
}[
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"file": "libexif/pentax/exif-mnote-data-pentax.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"63090266439464873986942635232246469126",
"133352749772712821961584651055235107129",
"87180012295696138925344357238405859904"
],
"threshold": 0.9
},
"id": "CVE-2020-13113-94b8b898"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"file": "libexif/olympus/exif-mnote-data-olympus.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"171665474353090061899021564791197257152",
"116301063513059510679027604740839939787",
"33983948157538593294138539723360334410",
"231840623465655071498280023479608178034"
],
"threshold": 0.9
},
"id": "CVE-2020-13113-a2502673"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"63090266439464873986942635232246469126",
"225602874433340598213515522161546468010",
"215464518781960057437098919856189329355"
],
"threshold": 0.9
},
"id": "CVE-2020-13113-a2eb331e"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_pentax_load",
"file": "libexif/pentax/exif-mnote-data-pentax.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 3532.0,
"function_hash": "60821619512570704490696459539065569381"
},
"id": "CVE-2020-13113-af3fbf42"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"file": "libexif/fuji/exif-mnote-data-fuji.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"63090266439464873986942635232246469126",
"133352749772712821961584651055235107129",
"59814921405938895402439206079570764350"
],
"threshold": 0.9
},
"id": "CVE-2020-13113-b11b808f"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_fuji_load",
"file": "libexif/fuji/exif-mnote-data-fuji.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2842.0,
"function_hash": "20638438429645367164789719521734894738"
},
"id": "CVE-2020-13113-b8c82fdb"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_olympus_load",
"file": "libexif/olympus/exif-mnote-data-olympus.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 6180.0,
"function_hash": "287078706475236992644152500043678847654"
},
"id": "CVE-2020-13113-d6752acb"
},
{
"source": "https://github.com/libexif/libexif/commit/ec412aa4583ad71ecabb967d3c77162760169d1f",
"signature_version": "v1",
"target": {
"function": "exif_mnote_data_canon_load",
"file": "libexif/canon/exif-mnote-data-canon.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2658.0,
"function_hash": "191996382206296598990556007166730683120"
},
"id": "CVE-2020-13113-d9365afb"
}
]
"2026-05-18T18:27:01Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-13113.json"