PT-2007-7490 · Libexif+1 · Libexif+1
Sean Larsson
·
Published
1970-01-01
·
Updated
2018-10-17
·
CVE-2006-4168
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Libexif versions prior to 0.6.16
Description
The issue is caused by an integer overflow in the
exif data load data entry function, which can lead to a denial of service or execution of arbitrary code via an image with many EXIF components, triggering a heap-based buffer overflow. This can result in a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.Recommendations
For Libexif versions prior to 0.6.16, update to version 0.6.16 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
exif data load data entry function until a patch is available. Avoid using images with many EXIF components in the affected API endpoints until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libexif
Red Hat