CVE-2020-13114: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
- Libexif Project Libexif: before 0.6.22 (fixed in 0.6.22)
- Opensuse Leap: version 15.1 only
Published 2020-05-21. Last modified 2026-06-17.