9.3
CVSSv2

CVE-2007-2645

Published: 14/05/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif prior to 0.6.14 allows user-assisted remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.

Vulnerable Product Search on Vulmon Subscribe to Product

libexif libexif 0.6.12

libexif libexif 0.6.13

libexif libexif 0.6.9

libexif libexif 0.5

libexif libexif 0.5.12

libexif libexif 0.6.11

Vendor Advisories

Debian Bug report logs - #424775 CVE-2007-2645: libexif 0614 fixes security issue Package: libexif; Maintainer for libexif is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Stefan Fritsch <sf@sfritschde> Date: Thu, 17 May 2007 09:54:02 UTC Severity: grave Tags: security ...
Victor Stinner discovered that libexif did not correctly validate the size of some EXIF header fields By tricking a user into opening an image with specially crafted EXIF headers, a remote attacker could cause the application using libexif to crash, resulting in a denial of service ...

Exploits

source: wwwsecurityfocuscom/bid/23927/info The libexif library is prone to an integer-overflow vulnerability because the software fails to properly ensure that integer math operations do not result in overflows Successful exploits of this vulnerability allow remote attackers to execute arbitrary machine code in the context of an applica ...