PT-2009-6117 · None · Libexif

Josh Bressers

·

Published

2009-11-20

·

Updated

2023-02-13

·

CVE-2009-3895

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libexif version 0.6.18
Description The issue is related to a heap-based buffer overflow in the exif entry fix function, which can be triggered by an invalid EXIF image. This could lead to a denial of service or potentially allow the execution of arbitrary code.
Recommendations For libexif version 0.6.18, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2009-3895

Affected Products

Libexif