PT-2007-7513 · Exiv2 · Exiv2

Published

1970-01-01

·

Updated

2024-07-19

·

CVE-2007-6353

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions exiv2 library (affected versions not specified)
Description The issue is related to an integer overflow in the exif.cpp file of the exiv2 library, which allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-03720
BDU:2015-03721
BDU:2015-03722
BDU:2015-03723
CVE-2007-6353
DSA-1474-1
OPENSUSE-SU-2024:10747-1

Affected Products

Exiv2