PT-2007-7535 · Libexif · Libexif

Published

1970-01-01

·

Updated

2018-10-16

·

CVE-2007-2645

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libexif versions prior to 0.6.14 libexif versions prior to 0.6.15
Description The issue involves an integer overflow in the exif data load data entry function in exif-data.c, which can be exploited by user-assisted remote attackers via crafted EXIF data, potentially leading to a denial of service or execution of arbitrary code. The variables doff and s are involved in this issue. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For libexif versions prior to 0.6.14, update to version 0.6.14 or later. For libexif versions prior to 0.6.15, update to version 0.6.15 or later. As a temporary workaround, consider restricting the use of crafted EXIF data until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04632
BDU:2015-04918
BDU:2015-04919
BDU:2015-04920
BDU:2015-09577
CVE-2007-2645
DSA-1487-1

Affected Products

Libexif