PT-2007-7535 · Libexif · Libexif
Publicado
1970-01-01
·
Atualizado
2018-10-16
·
CVE-2007-2645
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libexif versions prior to 0.6.14
libexif versions prior to 0.6.15
Description
The issue involves an integer overflow in the exif data load data entry function in exif-data.c, which can be exploited by user-assisted remote attackers via crafted EXIF data, potentially leading to a denial of service or execution of arbitrary code. The variables
doff and s are involved in this issue. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.Recommendations
For libexif versions prior to 0.6.14, update to version 0.6.14 or later.
For libexif versions prior to 0.6.15, update to version 0.6.15 or later.
As a temporary workaround, consider restricting the use of crafted EXIF data until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Libexif