PT-2007-7490 · Libexif+1 · Libexif+1

Sean Larsson

·

Publicado

1970-01-01

·

Atualizado

2018-10-17

·

CVE-2006-4168

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Libexif versions prior to 0.6.16
Description The issue is caused by an integer overflow in the exif data load data entry function, which can lead to a denial of service or execution of arbitrary code via an image with many EXIF components, triggering a heap-based buffer overflow. This can result in a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For Libexif versions prior to 0.6.16, update to version 0.6.16 or later to resolve the issue. As a temporary workaround, consider restricting the use of the exif data load data entry function until a patch is available. Avoid using images with many EXIF components in the affected API endpoints until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02124
BDU:2015-02125
BDU:2015-02126
BDU:2015-04632
BDU:2015-04918
BDU:2015-04919
BDU:2015-04920
BDU:2015-09568
CVE-2006-4168
DSA-1310-1
RHSA-2007:0501
RHSA-2007_0501

Produtos afetados

Libexif
Red Hat