PT-2007-1055 · Libexif+1 · Libexif+1

Published

2007-12-19

·

Updated

2024-06-15

·

CVE-2007-6351

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: libexif versions 0.6.16 and earlier
Description: The issue allows context-dependent attackers to cause a denial of service, possibly involving the exif loader write function in exif loader.c. Multiple vulnerabilities in the libexif package can lead to a violation of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations: For libexif versions 0.6.16 and earlier, update to a version later than 0.6.16 to resolve the issue. As a temporary workaround, consider restricting the use of the exif loader write function in exif loader.c until a patch is available. Avoid using crafted EXIF tags in image files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06307
BDU:2015-06310
BDU:2015-09617
CVE-2007-6351
DSA-1487-1
OPENSUSE-SU-2024:10939-1
RHSA-2007:1165
RHSA-2007_1165

Affected Products

Red Hat
Libexif