PT-2007-7535 · Libexif · Libexif

Publicado

1970-01-01

·

Atualizado

2018-10-16

·

CVE-2007-2645

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libexif versions prior to 0.6.14 libexif versions prior to 0.6.15
Description The issue involves an integer overflow in the exif data load data entry function in exif-data.c, which can be exploited by user-assisted remote attackers via crafted EXIF data, potentially leading to a denial of service or execution of arbitrary code. The variables doff and s are involved in this issue. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For libexif versions prior to 0.6.14, update to version 0.6.14 or later. For libexif versions prior to 0.6.15, update to version 0.6.15 or later. As a temporary workaround, consider restricting the use of crafted EXIF data until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-04632
BDU:2015-04918
BDU:2015-04919
BDU:2015-04920
BDU:2015-09577
CVE-2007-2645
DSA-1487-1

Produtos afetados

Libexif