PT-2012-6321 · Libexif+3 · Libexif+3
Yunho Kim
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2012-2836
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libexif versions prior to 0.6.21
libexif-devel versions prior to 0.6.21
libexif-0.6.21 (affected versions not specified for specific Linux distributions)
Description
The issue concerns multiple vulnerabilities in the libexif package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out remotely. The exif data load data function in exif-data.c in the EXIF Tag Parsing Library allows remote attackers to cause a denial of service or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
Recommendations
For versions prior to 0.6.21, update to version 0.6.21 or later to resolve the issue.
As a temporary workaround, consider disabling the
exif data load data function until a patch is available.
Restrict access to the vulnerable libexif module to minimize the risk of exploitation.
Avoid using crafted EXIF tags in images until the issue is resolved.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Libexif