CVE-2020-0093

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-0093

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-0093.html

OS impact

OSVersionStatusFixed in
arch archfixed0.6.22-1
suse slesaffected
debian debianbookwormfixed0.6.21-8
debian debianbullseyefixed0.6.21-8
debian debianforkyfixed0.6.21-8
debian debiansidfixed0.6.21-8
debian debiantrixiefixed0.6.21-8

References

Verify integrity in audit chain (admin only). AS-IS.