You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
Our tool have found that this repo reuse some of the libexif code and may cause a vulnerability. Several buffer over-reads in EXIF MakerNote handling could have lead to information disclosure and crashes. It shares a similarity to the CVE-2020-13112 and the fix is libexif/libexif@435e21f. Would you can help to check if this bug is true? If it's true, maybe you can fix it by the patch I mentioned before, or I'd like to open a PR for that if necessary. Thank you for your effort and patience!
Hi,
Our tool have found that this repo reuse some of the libexif code and may cause a vulnerability. Several buffer over-reads in EXIF MakerNote handling could have lead to information disclosure and crashes. It shares a similarity to the CVE-2020-13112 and the fix is libexif/libexif@435e21f. Would you can help to check if this bug is true? If it's true, maybe you can fix it by the patch I mentioned before, or I'd like to open a PR for that if necessary. Thank you for your effort and patience!