Exiv2 - Corrupted EXIF Data Denial of Service

Related Vulnerabilities: CVE-2005-4676  
Publish Date: 26 Jan 2006
                							

                source: http://www.securityfocus.com/bid/16400/info

Exiv2 is susceptible to a denial-of-service vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input data before attempting to read it, resulting in an out-of-bounds memory access crash.

This issue allows attackers to crash applications that use the affected library to process malicious image data. Depending on the nature of applications, this may be local or remote in nature.

This issue is present in Exiv2 versions prior to 0.9.

https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/27140.jpg